OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: revelation, snitch, openPass...

From: Alex Lambert (alambertquickfire.org)
Date: Thu Jun 12 2003 - 11:59:57 CDT


Alisson,

Briefly, any window can touch any other window. Using the API, windows can
talk to each other (including changing others' controls, like the password
box).

There is a paper titled "Exploiting design flaws in the Win32 API for
privilege escalation" which discusses some of these problems available at
http://www.astalavista.com/library/basics/guides/Next-GenerationWin32exploit
s.htm.

apl

----- Original Message -----
From: <averaslarc.usp.br>
To: <security-basicssecurityfocus.com>; <secprogsecurityfocus.com>
Sent: Thursday, June 12, 2003 9:59 AM
Subject: revelation, snitch, openPass...

> Hi folks,
>
> I was wondering if someone know how these programs work. They 'reveal'
> passwords shown as **** in texboxes.
>
> Does anyone have any sourcecode? Explanation on how then work?
>
>
> Thans a lot,
>
> Alisson