funsec mailing list archives

Re: Is The .WMF Exploit A ConsPiracy Gone Bad?


From: Gadi Evron <ge () linuxbox org>
Date: Sat, 14 Jan 2006 16:48:36 +0200

Thomas Mannfred Carlsson wrote:
On 13 Jan 2006 at 19:40, Thomas Mannfred Carlsson wrote:


Can anyone here who has experimented with the
WMF vulnerability confirm or deny that portion of the Gibson announcement (i.e. that the vulnerability can only be triggered in Windows systems with Size = 1)?


Just as a followup, a quick look at published WMF exploits to date suggest that successful exploitation can use different sizes than 1 (e.g. 4 in Metasploit, 17 in Ilfak's tester).. so either Gibson has stumbled on something new/different (i.e. maybe he uses a different function number, and this is a whole new issue), or then it may simply be a coding/interpretation error in his testbed (in which case my heart goes out to the lad, I'm sure we all know what it's like to discover something seemingly unprecedented and then force ourselves to calmly and carefully recheck the data, processes etc before drawing any significant conclusions).

Maybe it's another planned disinformation campaign.
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: