Metasploit mailing list archives

WinXP SP2 DEP Breaked


From: moises.teixeira at vianw.pt (Moises Teixeira)
Date: Tue, 1 Feb 2005 01:12:57 -0000


A Russian security company claims it found a way to beat a security measure
in Microsoft's Windows XP Service Pack 2, a major update aimed at securing
customers' PCs. 

The SP2 measure, known as Data Execution Protection, is intended to prevent
would-be attackers from inserting rogue code into a PC's memory and tricking
Windows into running the program. However, in a paper published Friday,
Moscow-based Positive Technologies said two minor mistakes in the
implementation of the technology allow a knowledgeable programmer to
sidestep the protection.
Continue at 
http://news.com.com/Report+Major+Windows+security+update+foiled/2100-1002_3-
5555448.html

Great Doc over here
http://www.maxpatrol.com/ptmshorp.asp

And pdf file with code expl code

Regards..
Moiro






Current thread: