Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
1–10 of 56 posts
Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#2Hats off!
Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#3Wow. It seems as if this has been discovered by rigorous manual inspection of the code (as opposed to just fuzzing the binary to death). Hats off!
I discovered this via a coverage based fuzzing engine with a dictionary (containing those magic numbers). Said fuzzing engine is similar to libFuzzer, but I have designed it with a focus on fuzzing closed source Windows binaries (PE).
Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#4Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#5Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#6You sir are a genius. Hoping for more posts of a similar nature and bookmarking now.
Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#7You sir are a genius. Hoping for more posts of a similar nature and bookmarking now.
Wow, thanks! That means a lot to me. Honestly, I didn't expect this to interest anyone.
Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#8Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#9Take a lesson - always write parsers in C and then execute them as root, and be sure to send as much malicious content to them as possible. Bonus points for hooking it up to the internet.
Re: Avast Antivirus Remote Stack Buffer Overflow with Magic Numbers
#10You sir are a genius. Hoping for more posts of a similar nature and bookmarking now.
Wow, thanks! That means a lot to me. Honestly, I didn't expect this to interest anyone.