OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-Disclosure] Local DoS in windows.

Valdis.Kletnieksvt.edu
Date: Sat Oct 11 2003 - 20:05:29 CDT


On Sun, 12 Oct 2003 02:18:16 +0200, Richard Spiers <dksaarthunix.za.net>
said:
> whoopee!. Bleh. Really a security issue? Same thing happens if you have
show
> windows content enabled and you drag around a window, as long as your
> dragging the window, the cpu will remain close to 100 % usage.
Significant?

Probably not directly, but possibly indirectly.

The questions are, of course:

1) Is the 100% cycle sucking done as a pre-emptible thing, or can you
cpu-starve something else using it?

2) Is there some *other* security-related API that botches incorrectly if
it's
cpu-starved?

> No, unless its proof of some shoddy coding of some-sort.

A hammer is a useful tool for finding non-impact-resistant screws......

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  • application/ms-tnef attachment: stored