AKB Forums

Go Back   AKB Forums > Technical sections > Software Security
Home Register Blogs FAQ Members List Calendar Downloads Arcade Mark Forums Read

Software Security Discussing software security algorithms, tricks, vulnerabilities

Troubles when posting message? Click here! :: Ïðîáëåìû ñ îòïðàâëåíèåì ñîîáùåíèÿ? Íàæìèòå ñþäà!

Reply
 
LinkBack Thread Tools Display Modes
Old Jan 31, 2005, 19:04   #1
Administrator
 
acid's Avatar
 
Join Date: Sep 2001
Location: Yerevan, Armenia
Posts: 7,086
Blog Entries: 15
Rep Power: 10
Reputation: 251
Defeating Microsoft Windows XP SP2 Heap protection and DEP bypass

Published 28th January 2005.
Problem
In October 2004 it was discovered by MaxPatrol team that it is possible to defeat Microsoft® Windows® XP SP2 Heap protection and Data Execution Prevention mechanism. As a result it is possible to implement:
  1. Arbitrary memory region write access (smaller or equal to 1016 bytes)
  2. Arbitrary code execution
  3. DEP bypass.
Details are described in the article by our expert: PDF format, HTML format.
Solution
As a temporary security measure we've developed simple utility PTmsHORP, which allows restriction of lookaside list creation, governed by a special global flag.
Download PTmsHORP (21 Kb)
During the first execution this program shows the list of applications which already have this flag set. In order to activate this safety flag for other applications you just need to add the name of the executable file to the list. Any time you can review or modify the list of protected applications by running PTmsHORP again.
Warning. The flag, while enabled, may decrease the application performance.

http://www.maxpatrol.com/ptmshorp.asp
__________________
Chat with acid


acid is offline   Reply With Quote Quote selected
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Default Passwords acid Software Security 4 Feb 12, 2006 06:01
Microsoft: SP2 Will Not Install on Pirated Copies of XP acid Software Security 9 Nov 6, 2004 19:30


All times are GMT. The time now is 02:58.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
This board was founded on September 29, 2001
Powered by Viper Internet

Affordable Web Hosting | ParevNet

Buy text link