funsec mailing list archives
Re: Is The .WMF Exploit A ConsPiracy Gone Bad?
From: Gadi Evron <ge () linuxbox org>
Date: Sat, 14 Jan 2006 16:48:36 +0200
Thomas Mannfred Carlsson wrote:
On 13 Jan 2006 at 19:40, Thomas Mannfred Carlsson wrote:Can anyone here who has experimented with theWMF vulnerability confirm or deny that portion of the Gibson announcement (i.e. that the vulnerability can only be triggered in Windows systems with Size = 1)?Just as a followup, a quick look at published WMF exploits to date suggest that successful exploitation can use different sizes than 1 (e.g. 4 in Metasploit, 17 in Ilfak's tester).. so either Gibson has stumbled on something new/different (i.e. maybe he uses a different function number, and this is a whole new issue), or then it may simply be a coding/interpretation error in his testbed (in which case my heart goes out to the lad, I'm sure we all know what it's like to discover something seemingly unprecedented and then force ourselves to calmly and carefully recheck the data, processes etc before drawing any significant conclusions).
Maybe it's another planned disinformation campaign. _______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad?, (continued)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Valdis . Kletnieks (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Blanchard, Michael (InfoSec) (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Todd Towles (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Don Kennedy (Jan 13)
- Re[2]: Is The .WMF Exploit A ConsPiracy Gone Bad? Pierre Vandevenne (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Don Kennedy (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Todd Towles (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Larry Seltzer (Jan 13)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Blue Boar (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Thomas Mannfred Carlsson (Jan 13)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Thomas Mannfred Carlsson (Jan 14)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Gadi Evron (Jan 14)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Valdis . Kletnieks (Jan 14)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Technocrat (Jan 14)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Nick FitzGerald (Jan 14)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Gadi Evron (Jan 15)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Ronaldo Vasconcellos (Jan 15)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Valdis . Kletnieks (Jan 15)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Nick FitzGerald (Jan 15)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Matt Sergeant (Jan 15)
- RE: Is The .WMF Exploit A ConsPiracy Gone Bad? Larry Seltzer (Jan 13)
- Message not available
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Jordan Wightman (Jan 15)
- Re: Is The .WMF Exploit A ConsPiracy Gone Bad? Dude VanWinkle (Jan 15)