Full Disclosure mailing list archives
Re: Windows .ANI LoadAniIcon Stack Overflow
From: "ad () heapoverflow com" <ad () heapoverflow com>
Date: Mon, 02 Apr 2007 00:16:26 +0200
From the published poc yes vista is vulnerable , the poc doesn't exploit it but shows enough.. The whole windows browser crashes when you try to open the folder of the malicious .ani file, can't even attach it to an email because thunderbird crashes when I'm browsing to attach the .ani, EIP is overwritten by some wrong datas near the shellcode, . To resume you don't have to open the file on vista, displaying it is enough, there is less user interaction required to exploit that bug on vista than older windows os, surprising... ...or not =) Larry Seltzer wrote:
It is completely possible to execute shellcode if we can do some DEPbypass (ie. ret2libc attack, etc..) In Vista this should have problems because of ASLR, right? I'm beginning to think that web-based attacks with this in Vista aren't really so scary. Even if you can get them to execute what can you really do in IE protected mode? You need to get the user to run the ANI outside of IE. Can anyone say what actually happens if you read an e-mail in the Vista Mail program with an attack ANI embedded? Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blog.eweek.com/blogs/larry%5Fseltzer/ Contributing Editor, PC Magazine larryseltzer () ziffdavis com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ .
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Windows .ANI LoadAniIcon Stack Overflow Larry Seltzer (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow dev code (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow Larry Seltzer (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow ad () heapoverflow com (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow ad () heapoverflow com (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow -> Its ok, its in IE Protected Mode Haroon Meer (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow Dave Aitel (Apr 02)
- Re: Windows .ANI LoadAniIcon Stack Overflow Larry Seltzer (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow Alexander Sotirov (Apr 02)
- Re: Windows .ANI LoadAniIcon Stack Overflow Thierry Zoller (Apr 02)
- Re: Windows .ANI LoadAniIcon Stack Overflow Larry Seltzer (Apr 02)
- Re: Windows .ANI LoadAniIcon Stack Overflow Jason Areff (Apr 02)
- Re: Windows .ANI LoadAniIcon Stack Overflow Larry Seltzer (Apr 02)
- Re: Windows .ANI LoadAniIcon Stack Overflow Jason Areff (Apr 02)
- Re: Windows .ANI LoadAniIcon Stack Overflow Larry Seltzer (Apr 01)
- Re: Windows .ANI LoadAniIcon Stack Overflow dev code (Apr 01)