Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Need Advice for job in Microsoft

Topic created on: August 13, 2010 08:06 CDT by voila .

hello friends ,
I m voila , i m college Computer Science (B.Tech\B.E) . Actually i have done a research on windows 7  which is "is  Win 7 able to secure third party services running on it" .
So to demonstrate it , I create a client/server programm , with server has a vulnerability .
So my task was to exploit this vulnerability to gain control over the system i.e WIN 7  .

In this research assumptions are :
1. Default installation of Windows 7 (DEP and ASLR are enable)
2. As test "server" is third party service , so it donot have ASLR enabled .

As a result of my research i was able to exploit the server on WIN 7 even on WIN Vista also .

So now i need your advice , should i apply in Microsoft with this research paper in my arsenal ???

Please donot give me any absurd advice , because your advice can affects my decision , and after all its about my carrer

Thanks in advance .

Voila

  cod     August 16, 2010 05:04.28 CDT
Without details is not possible to answer your question. You wrote a vulnerable service.. but my first question is:
After exploiting the vulnerability in service what you can do? How do you bypass DEP and ASLR mitigation?

  jumpzero     August 16, 2010 07:52.23 CDT
i guess voila is tryin to say that he assumed that the server application is a third party app, so he linked it without aslr option.

well voila, no one can tell if you can get a job in a company or not. in my humble opinion, disabling aslr has no meanings for microsoft, cuz IDEs like visual studio is now having aslr options for default when they compile&link. and it's not that hard to see exploits bypass dep and aslr using various ways. i don't think ms is going to be interested with your work, but man, who knows?

i think there is no reason for you 'not' to apply. go for it.

  voila     August 16, 2010 10:16.25 CDT
hii .
thanks "cod" and "jumpzero" for your reply .  Yes "jumpzero" is right , i assume that my test "server" is third party app , so i linked it , without aslr option . but it is what i want to show , because many third party app . are not linked with aslr due to compatibility factor and many other resons also  .. more over some vendors donot use IDE like Vc++ .

"cod" -> well as ASLR is enabled for dlls   , so i cannot use Retlib attack  , so i overwrite the EIP to return to the code segment of my test "server" itself ( becuase it is only module for which aslr in not enabled) in such a way to bypass code that authenticate user for correct username and password .

Well i had a big discussion with "gynvael" and  he direct me toward right direction ... special thanks to him ...
and thanks to you guys also ..

Note: Registration is required to post to the forums.

Active in Last 5 Minutes
waleedassar

There are 28,224 total registered users.


Recently Created Topics
Reverse Engineering ...
Jan/23
Career: DoD Agency I...
Jan/22
"Disappearing&q...
Jan/17
Career: Software Sec...
Jan/11
Where is the call st...
Jan/07
IDA Pro 6.1 Breakpoi...
Jan/01
How to create data s...
Dec/30
can i search all mod...
Dec/23
IDA symbol table exp...
Dec/20
An anti-attach trick
Dec/17


Recent Forum Posts
Reverse Engineering ...
NirIzr
"Disappearing&q...
NirIzr
Reverse Engineering ...
charlie
"Disappearing&q...
charlie
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
An anti-attach trick
waleeda...
An anti-attach trick
Bass
Looking for value in...
NirIzr


Recent Blog Entries
cmathieu
Feb/07
Hacker Carnival

waleedassar
Feb/06
OllyDbg v1.10 And Hardware ...

waleedassar
Jan/31
Yet Another Anti-Debug Trick

RolfRolles
Jan/22
Finding Bugs in VMs with a ...

waleedassar
Jan/13
An OllyDbg Bug Disables Sof...

More ...


Recent Blog Comments
waleedassar on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/07
OllyDbg v1.10 And Hardware ...

NirIzr on:
Feb/05
Yet Another Anti-Debug Trick

trolotou on:
Feb/05
Doudoune Moncler -Pennies F...

waleedassar on:
Feb/01
Yet Another Anti-Debug Trick

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit