Metasploit mailing list archives

how to identify the pattern


From: suman.saini at ariosesoftware.com (Suman Saini)
Date: Thu, 13 Sep 2007 16:15:08 +0530

Hi all.. :)

I tried to test "ms06_001_wmf_setabortproc"  exploit and it was successfully tested, thanks for help. Now i m tryin to 
write a siganture for the detection of this attack but i m not able to identity the pattern as the wmf is gzipped. 

looking forward to some help :)

Thanks
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.metasploit.com/pipermail/framework/attachments/20070913/08ca57cd/attachment.htm>


Current thread: