lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Mon, 2 Apr 2007 16:32:20 +0200
From: Thierry Zoller <Thierry@...ler.lu>
To: "Larry Seltzer" <Larry@...ryseltzer.com>
Subject: Re: Windows .ANI LoadAniIcon Stack Overflow

Dear Larry Seltzer,

I did not ask to have an explanation about Heap based exploits.

LS>I'm sure any HIPS would block it. But like DEP they're not on
LS> in Windows by default.
That's where you are wrong larry, if you have an NX capable CPU
("hardware enforced") DEP is turned on by default on all and every
process. Software DEP is not really DEP it's more like SafeSEH...


-- 
http://secdev.zoller.lu
Thierry Zoller
Fingerprint : 5D84 BFDC CD36 A951 2C45  2E57 28B3 75DD 0AC6 F1C7

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux