[VulnDiscuss] Re: Preventing exploitation with rebasing

snakebyte / Eric Sesterhenn <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Hi,

your rebasing has one problem, once exploit  code is loaded it can scan
the memory or the executables import table to get access to kernel32.dll
then it might use LoadLibrary and GetProcAddress to get every DLL
function it wants to. Viruses are doing this for years :)
Just makes the "shell"-code bigger, thats all

 cu Eric

-- 
 www.againsttcpa.com -- 1984 might be true, just 30 years later 
 www.snake-basket.de -- just my stuff
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+PvZW7rejnZVRpKIRAp8FAJ4wesZbVuHK//clsXfTY2VzK3wQOQCglGVh
PObR/xDW4Q7RePITGu7YrWY=
=CDcx
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.