OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Full-disclosure] "WinProxy 6.0 R1c" Remote Stack/SEH Overflow Exploit

From: FistFucker (FistFuXXergmx.de)
Date: Sat Jan 07 2006 - 12:19:33 CST


The PoC exploit for this issue is attached to this e-mail. It has been
successfully tested under Microsoft Windows XP Professional (german, SP2).
Remote attackers can bypass the SEH frames protection of the operating
system by calling a POP/POP/RET sequence in the dynamic link libraries of
the Panda Antivirus scanning engine.

-FistFucker (aka FistFuXXer)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/