Re: VisualBasic auditing

From: Cesar (cesarc56@yahoo.com)
Date: 02/18/03

  • Next message: exce@boxen.netwinder.nu: "Is this an off-by-one overflow?"
    Date: Tue, 18 Feb 2003 12:12:02 -0800 (PST)
    From: Cesar <cesarc56@yahoo.com>
    To: vuln-dev@securityfocus.com
    
    

    You can exploit SQL injection in Visual Basic
    applications. Also some applications have
    authentication (users and passwords) information built
    in the code, so you can look at the .exe using strings
    (from sysinternals), hex editors, etc.

    Cesar.
    --- Some d00d <shavidi@yahoo.com> wrote:
    >
    >
    >
    >
    > Hi folks
    >
    >
    >
    >
    > I am auditing some network application and a
    > significant number of them are written in MS Visual
    > Basic. Have anyone done some work on exploiting VB
    > software before? I assume that traditional methods
    > such
    > as buffer overflows will not work here.
    >
    >
    >
    >
    > Are there any tools around for this (such as VB
    > disassemblers and de-scramblers)?
    >
    >
    > Can you point me to any sources of information?
    >
    >
    >
    >
    > Thanks in advance, SD

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Shopping - Send Flowers for Valentine's Day
    http://shopping.yahoo.com



    Relevant Pages

    • Invalid Password
      ... I signed out of all applications (ie yahoo, ebay, hotmail) ... needed space, but if that was the case, they I would think ...
      (microsoft.public.security)
    • Re: Why no serious MS Application in .NET yet ??
      ... from the user's point-of-view Yahoo may be an application... ... computer the Browser itself is the application. ... >> However, we see the same native office applications are coming out again, ... > application is the totality of the useful services, applets, web services ...
      (microsoft.public.dotnet.framework)
    • Re: Why no serious MS Application in .NET yet ??
      ... from the user's point-of-view Yahoo may be an application... ... computer the Browser itself is the application. ... >> However, we see the same native office applications are coming out again, ... > application is the totality of the useful services, applets, web services ...
      (microsoft.public.dotnet.framework.performance)
    • Re: Why no serious MS Application in .NET yet ??
      ... from the user's point-of-view Yahoo may be an application... ... computer the Browser itself is the application. ... >> However, we see the same native office applications are coming out again, ... > application is the totality of the useful services, applets, web services ...
      (microsoft.public.dotnet.general)
    • Re: Why no serious MS Application in .NET yet ??
      ... from the user's point-of-view Yahoo may be an application... ... computer the Browser itself is the application. ... >> However, we see the same native office applications are coming out again, ... > application is the totality of the useful services, applets, web services ...
      (microsoft.public.dotnet.framework.clr)