Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: A little help??

Re: A little help??

From: Inventor UCL <digiwind_at_hotmail.com>
Date: 11 Mar 2004 05:22:56 -0000
('binary' encoding is not supported, stored as-is) In-Reply-To: <200403091916.i29JGTWk077146_at_mailserver2.hushmail.com>

>Using the MS ASN.1 vulnerability as an example, I have a question:
>How was Eeye able to determine which function the heap overflow existed
>in. I have been able to trace through the msasn1.dll, but I can't figure

Probably based on the earlier ASN.1 vulnerability in OpenSSL.

>out how to find the exact function that contains the overflow.

Look up Fuzzers. Might be helpful.

inv_
Received on Mar 11 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos