Windows fuzz

From: Blue Boar (BlueBoar@thievco.com)
Date: 10/30/01


Date: Mon, 29 Oct 2001 16:41:44 -0800
From: Blue Boar <BlueBoar@thievco.com>
Subject: Windows fuzz
To: vuln-dev@securityfocus.com
Message-id: <3BDDF748.E13BAD83@thievco.com>

I was looking at this page today:
http://www.cs.wisc.edu/~bart/fuzz/fuzz-nt.html
After seeing it referenced in an NTBugtraq post.

Naturally, I got to wondering if the problems described there could
be taken advantage of for privilege elevation. It would involve
being able to send Windows messages to another app, probably on the
same physical machine. Anyone done anything along these lines,
or can anyone point me at where I can read up on the security
surrounding message passing?

                                BB