OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: cipher.exe overflow

From: K. K. Mookhey (ctonii.co.in)
Date: Wed Apr 23 2003 - 00:35:39 CDT


Hi Moran,
Windows 2000 is full of local buffer overflows. We too reported a couple to MS, and then stopped looking. There was a discussion some time back on Nslookup having a local BO. I think the thread is here:
http://www.securityfocus.com/archive/82/315781

K. K. Mookhey
CTO,
Network Intelligence India Pvt. Ltd.
Web: www.nii.co.in
=================================
Security Auditing Software - AuditPro
http://www.nii.co.in/products.html
=================================

>
> there is a problem with cipher.exe.
> overflow occurs when you add string of more than 256 chars.
> example:
> c:\> cipher.exe <A * 257>
>
> program will crash.
>