📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Need Advice for job in Microsoft

Topic created on: August 13, 2010 08:06 CDT by voila .

hello friends ,
I m voila , i m college Computer Science (B.Tech\B.E) . Actually i have done a research on windows 7  which is "is  Win 7 able to secure third party services running on it" .
So to demonstrate it , I create a client/server programm , with server has a vulnerability .
So my task was to exploit this vulnerability to gain control over the system i.e WIN 7  .

In this research assumptions are :
1. Default installation of Windows 7 (DEP and ASLR are enable)
2. As test "server" is third party service , so it donot have ASLR enabled .

As a result of my research i was able to exploit the server on WIN 7 even on WIN Vista also .

So now i need your advice , should i apply in Microsoft with this research paper in my arsenal ???

Please donot give me any absurd advice , because your advice can affects my decision , and after all its about my carrer

Thanks in advance .

Voila

  cod     August 16, 2010 05:04.28 CDT
Without details is not possible to answer your question. You wrote a vulnerable service.. but my first question is:
After exploiting the vulnerability in service what you can do? How do you bypass DEP and ASLR mitigation?

  jumpzero     August 16, 2010 07:52.23 CDT
i guess voila is tryin to say that he assumed that the server application is a third party app, so he linked it without aslr option.

well voila, no one can tell if you can get a job in a company or not. in my humble opinion, disabling aslr has no meanings for microsoft, cuz IDEs like visual studio is now having aslr options for default when they compile&link. and it's not that hard to see exploits bypass dep and aslr using various ways. i don't think ms is going to be interested with your work, but man, who knows?

i think there is no reason for you 'not' to apply. go for it.

  voila     August 16, 2010 10:16.25 CDT
hii .
thanks "cod" and "jumpzero" for your reply .  Yes "jumpzero" is right , i assume that my test "server" is third party app , so i linked it , without aslr option . but it is what i want to show , because many third party app . are not linked with aslr due to compatibility factor and many other resons also  .. more over some vendors donot use IDE like Vc++ .

"cod" -> well as ASLR is enabled for dlls   , so i cannot use Retlib attack  , so i overwrite the EIP to return to the code segment of my test "server" itself ( becuase it is only module for which aslr in not enabled) in such a way to bypass code that authenticate user for correct username and password .

Well i had a big discussion with "gynvael" and  he direct me toward right direction ... special thanks to him ...
and thanks to you guys also ..

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit