logo       

Re: Nitin Kumar & Vipin Kumar: "please remember to givenecessary credit to : msg#00066

security.dailydave

Subject: Re: Nitin Kumar & Vipin Kumar: "please remember to givenecessary credit to the authors" PKB.

On 26 April 2007 22:23, Dave Korn wrote:


> I will concede that they've done at least some genuine work in reversing
> the integrity checks in the loader, but that's fairly routine stuff;
> bypassing a check by altering the test in a branch instruction is pretty
> trivial, it's about on the level of finding an infinite lives poke in a
> computer game.

Now I see this coming back at me on the list, it occurs to me to mention a
*far* more relevant comparison: it's exactly what Hoglund showed in his
earliest work about hot-patching a one-byte bypass into SeAccessCheck. That
was back in NT3.51 days, 1995 or so IIRC.


cheers,
DaveK
--
Can't think of a witty .sigline today....


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise