OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Barnaby Jack (dspyritSUBDIMENSION.COM)
Date: Fri Apr 27 2001 - 21:19:45 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    We've now had the opportunity to do some testing on different
    hosts/configurations... the results differed from ours but yet still
    provided exploitable conditions.

    The breaks this time were during calls to RtlAllocateHeap and RtlFreeHeap -
    with careful register manipulation it is STILL possible to execute custom
    code.

    More detailed info later.

    -dark spyrit.