On 4/2/07, <b class="gmail_sendername">Larry Seltzer</b> <<a href="mailto:Larry@larryseltzer.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">Larry@larryseltzer.com</a>> wrote:<div><span class="gmail_quote">
</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
AS> A much simpler solution is to use heap spraying (which works fine on<br><br>AS> Vista) for systems that don't have DEP enabled.<br>TZ> Are we talking Sofware DEP or Hardware enforce DEP ?<br><br>Heap spraying implies running code in the heap,
</blockquote><div><br><br>Actually, um.. no.. it doesn't<br> </div><br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">which any DEP should
<br>block. There are all kinds of software techniques that would detect heap<br>spraying. I'm sure any HIPS would block it. </blockquote><div><br>Most likely not with regard to sotirov's new heap library stuff.<br>
</div><br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Larry Seltzer<br>eWEEK.com Security Center Editor<br><a href="http://security.eweek.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://security.eweek.com/</a><br><a href="http://blog.eweek.com/blogs/larry%5Fseltzer/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://blog.eweek.com/blogs/larry%5Fseltzer/</a><br>Contributing Editor, PC Magazine
<br><a href="mailto:larryseltzer@ziffdavis.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
larryseltzer@ziffdavis.com</a></blockquote><div><br><br>How do you get to be in that position? Lot's of buzzword-tossing I'd have to guess.<br> </div></div>