[26567] in bugtraq

home help back first fref pref prev next nref lref last post

Re: White paper: Exploiting the Win32 API.

daemon@ATHENA.MIT.EDU (Florian Weimer)
Tue Aug 6 18:40:09 2002

To: "John Howie" <JHowie@securitytoolkit.com>
From: Florian Weimer <Weimer@CERT.Uni-Stuttgart.DE>
Date: Tue, 06 Aug 2002 22:51:46 +0200
In-Reply-To: <DAEF28A9E7214B46AE7C7C66861F6308E183@STKSRV1.securitytoolkit.com> ("John
 Howie"'s message of "Tue, 6 Aug 2002 10:44:17 -0700")
Message-ID: <87eldbww0t.fsf@CERT.Uni-Stuttgart.DE>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii

"John Howie" <JHowie@securitytoolkit.com> writes:

> This class of attack is not new, it has been discussed before. While you
> can assert that the blame lies with Microsoft (and I'll admit they do
> have some responsibility to address the problem you describe)

A bit of MSDN browsing revealed that Microsoft has already "fixed" the
vulnerabilites, despite the claim that this was impossible.  The
concepts are called "window stations" and "desktops", and there is
plenty of documentation.  Everything is there: separate sets of hooks,
separate message queues, and so on.

Maybe there are some flaws, but the overall design seems to be sound.

-- 
Florian Weimer 	                  Weimer@CERT.Uni-Stuttgart.DE
University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT                          fax +49-711-685-5898

home help back first fref pref prev next nref lref last post