|
|||||||||||
|
Re: NSLOOKUP.EXE
From: Mysq <mysq(at)mail.com>
Date: Fri Mar 21 2003 - 08:11:21 EST
Tested on Win2k pro SP3.
(128.518): Access violation - code c0000005 eax=42424242,ebx=7800110c ecx=41414141,edx=00000002 esi=01037fa0,edi=00000000 eip=01007dee,esp=0004fa38 ebp=00000000 I also couldn't see any of the exploit string in memory near the eip or esp memory addresses. I am not going to continue researching this issue due to the fact that it would only be remotly exploitable if arguments inputed by a remote user (which are not validated) are passed to nslookup on the server. I don't really see the point in a server application doing this. As a local exploit, the nslookup process runs with privilage of the user who executes it so that removes possibilty for privilage escalation. Question to BO guru's: How would it be possible to control the eip if only eax/ecx are overwritten ?
Best Regards to all,
-- __________________________________________________________ Sign-up for your own FREE Personalized E-mail at Mail.com http://www.mail.com/?sr=signupReceived on Fri Mar 21 16:13:55 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:38 EDT |
||||||||||
|
|||||||||||