Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 10th, 2012, 10:23 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Flash info leak leads to a fun vulnerability

http://zhodiac.hispahack.com/my-stuf...SLR_bypass.pdf

TLR Flash is vulnerable to a reliable info leak that allows ASLR to be bypassed making exploitation
of other vulnerabilities, on browsers, Acrobat Reader, MS Office and any process that can host
Flash, trivial like in the old days where no security mitigations were available. Patch immediately

(My personal note) I think it's silly when these get called "ASLR bypasses" because people get confused. This didn't really bypass ASLR, ASLR just wasn't fully supported. Had ASLR been fully supported it would have made this far less viable. It also highlights that a single area of address space not supporting ASLR (though the initial exploit wouldn't' care about ASLR) is often all it takes to construct ROP - so consider what you inject into processes, a single non-aslr DLL undermines the security of the entire program.
__________________

Last edited by Hungry Man : April 10th, 2012 at 10:34 PM.
  #2  
Old April 11th, 2012, 10:09 AM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,019
Default Re: Flash info leak leads to a fun vulnerability

Quote:
Originally Posted by Hungry Man
so consider what you inject into processes, a single non-aslr DLL undermines the security of the entire program.

Which I believe is one of the things Microsoft is trying to kill off with EPM.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #3  
Old April 11th, 2012, 04:09 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Flash info leak leads to a fun vulnerability

The problem is that the fixed address used for ROP in this case is an undocumented library that's actually provided by Windows and is always loaded into the same address.

So I'm wondering if all programs use/ have access to this because it's a major security hole if so - it's like a universal ASLR bypass.
__________________
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:36 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums