Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  How to exploit GDI API bug in browser environment?

Topic created on: October 15, 2009 04:39 CDT by static .

Hi , i am new to this forum , hope this topic is in right place.

have a look on this URL:
http://buzzworld.org/published.html

there is an entry called :
APS018
Microsoft GDI WMF Parsing Heap Overflow Vulnerability

Sebastian said :
the "best" exploitation vector is a browser since we can make use of heap spraying to get
fairly reliable code execution.

i search for an exploit using this method but i found nothing. how we can invoke api like that in browser environment?
is any GDI api invocable in browser environment?
is any windows api is invocable in browser environment?
(it make no sense,  using LoadLibraryA or GetProcAddress or createprocess can be dangerous)
fast response appreciated.

No posts found under this topic.
Note: Registration is required to post to the forums.

Active in Last 5 Minutes
NirIzr
Invisible

There are 28,225 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
cmathieu
Feb/07
Hacker Carnival

waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

More ...


Recent Blog Comments
waleedassar on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit