--
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
This list is supported by Institute of Information Security http://iisecurity.in
Learn information security at your own pace – eLearning programs at http://elearning.iisecurity.in
On the topic of release/reporting vulnerabilities: Just to maintain a
balance in this "ethical" world, its sometimes important not to do so
;-)
Regards,
-abhisek
--
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
This list is supported by Institute of Information Security http://iisecurity.in
Learn information security at your own pace – eLearning programs at http://elearning.iisecurity.in
Mostly true as you will hardly get a crash these days where you
trashed the EIP thats why I guess a lot of research work is going on
related to automatic classification of crashes as well as automatic
analysis of a given crash (backtracking, taint checking etc. etc.) If
you get even 10 unique crash for a software where you directly or
indirectly or even partially control registers like ECX, EAX, EDI then
from experience I think its worth examining in detail. Like who would
have thought NULL pointer dereferences (in the kernel) are exploitable
like 5 years back but in reality they are trivially exploitable (given
the kernel space and the user space overlaps and there is no
restriction on mapping NULL page).
Regards,
-abhisek
does anybody know a good application for static analysis besides
immunity's debugger which does static analysis automagically ?
thanks,
cons0ul
Regards,
-abhisek
--
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
This list is supported by Institute of Information Security http://iisecurity.in
Learn information security at your own pace – eLearning programs at http://elearning.iisecurity.in
----------
Sent via Nokia Email
there are more things in it i just found the cool utility PIN which works like JIT for pe binary so we can wrap around functins like heapalloc and heapfree
with proper automation and analysis it wiil speed up the process of bug hunting
Yash Kadakia
Office: +91-022-23612909
Office: +1-347-99-ITSEC (+1-347-994-8732)
Mobile: +91-9833375290
Blog: http://www.yashkadakia.com/
Sent on my BlackBerry® from Vodafone
Yash Kadakia
Office: +91-022-23612909
Office: +1-347-99-ITSEC (+1-347-994-8732)
Mobile: +91-9833375290
Blog: http://www.yashkadakia.com/
Sent on my BlackBerry® from Vodafone
-
TAS
http://twitter.com/p0wnsauc3