XP/Vista IGMP Buffer Overflow — Explained
HalvarFlake writes "With all the hoopla about the remotely exploitable, kernel-level buffer overflow discussed in today's security bulletin MS08-0001, what is the actual bug that triggers this? The bulletin doesn't give all that much information. This movie (Flash required) goes through the process of examining the 'pre-patch' version of tcpip.sys and comparing it against the 'post-patch' version of tcpip.sys. This comparison yields the actual code that causes the overflow: A mistake in the calculation of the required size in a dynamic allocation."
>This comparison yields the actual code that causes the overflow:
>A mistake in the calculation of the required size in a dynamic allocation
I hope no one else makes this mistake.
Hooray! Windows vulnerabilities are so commonplace now that there are public educational documentaries about their life-cycles and internals, so that the people can stay informed. Brilliant!
OMG! I thought it might be a bug, but thankfully it's just a mistake!
Engineering is the art of compromise.
Darn pesky kids and their fancy buffer overflows. I outta HEAP on the insults, but I'll try to stick to my PROGRAM of keeping my smoke STACK cool.
512 MB RAM, 20 GB disk, 200 GB transfer, five datacenters. $19.95/month.
*blink*
"Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
This movie (Flash required) goes through the process of examining the 'pre-patch' version of tcpip.sys and comparing it against the 'post-patch' version of tcpip.sys. This comparison yields the actual code that
See? And they said without FOSS, this couldn't be done!
You see? You see? Your stupid minds! Stupid! Stupid!
"It could be that the purpose of your life is only to serve as a warning to others." http://despair.com/mis24x30prin.html
Obligatory "Office Space" Quotes...
Tom Smykowski: It was a "Jump to Conclusions" mat. You see, it would be this mat that you would put on the floor... and would have different CONCLUSIONS written on it that you could JUMP TO.
Michael Bolton: That's the worst idea I've ever heard in my life, Tom.
Samir: Yes, this is horrible, this idea.
But that is the primary reason for