[Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow

Kristian Hermansen kristian.hermansen at gmail.com
Mon Apr 2 18:54:09 BST 2007


Dave Aitel <dave at immunityinc.com> wrote:
> ASRL has limited entropy and the attacker can continue to try exploits
> an infinite number of times (as Solar Eclipse points out). This means
> you can write a reliable Vista exploit, theoretically. I'll probably
> finish one up on Monday.

On 32-bit, yes, but 64-bit ASLR entropy means it is not very likely to
hit your offset :-)  Has anyone even attempted a 64-bit XP/Vista ANI
exploit?
-- 
Kristian Hermansen




Full-Disclosure is hosted and sponsored by Secunia.