[Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]

Sumit Siddharth sumit.siddharth at gmail.com
Tue Jan 3 04:30:34 GMT 2006


Dear All,
Sorry for the delayed response.
I  had success in exploiting it remotely by a simple javascript
<script>window.open("http://aa...");</script>. But i think it doesnt work
with some drivers.I am using XP ,professional, SP2. and firefox 1.0.6. I am
using a string of about 53,000 char to overflow the buffer.
Thanks
Sumit
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060103/00fdbba6/attachment.html 


Full-Disclosure is hosted and sponsored by Secunia.