[Full-disclosure] LSADump2 Crashing Windows

Nicolas RUFF nicolas.ruff at gmail.com
Mon Sep 5 12:55:11 BST 2005


> This is a bug in lsadump2 - there's a type mismatch in one of the
> functions, although I forget which one. Something is a pointer which
> shouldn't be, or vice versa. Once you fix that, it'll be good to go.

I also noticed that LSADump is *not* compatible with a NX-enabled
Windows, because the allocated memory where the code is injected is not
flagged as "executable".

The same problem affects Cain (www.oxid.it), for (I guess) it reuses the
same code.

Regards,
- Nicolas RUFF
Security Researcher @ EADS-CCR



Full-Disclosure is hosted and sponsored by Secunia.