[VulnDiscuss] Re: Preventing exploitation with rebasing
snakebyte / Eric Sesterhenn <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, your rebasing has one problem, once exploit code is loaded it can scan the memory or the executables import table to get access to kernel32.dll then it might use LoadLibrary and GetProcAddress to get every DLL function it wants to. Viruses are doing this for years :) Just makes the "shell"-code bigger, thats all cu Eric -- www.againsttcpa.com -- 1984 might be true, just 30 years later www.snake-basket.de -- just my stuff
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE+PvZW7rejnZVRpKIRAp8FAJ4wesZbVuHK//clsXfTY2VzK3wQOQCglGVh PObR/xDW4Q7RePITGu7YrWY= =CDcx -----END PGP SIGNATURE-----