<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Green Dam URL Processing Buffer Overflow exploit (meta)</title>
	<atom:link href="http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Fri, 12 Mar 2010 03:47:25 +0000</lastBuildDate>
	<generator>http://www.rec-sec.com</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
		<item>
		<title>By: seer[N.N.U]</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1061</link>
		<dc:creator>seer[N.N.U]</dc:creator>
		<pubDate>Fri, 10 Jul 2009 11:23:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1061</guid>
		<description>Wow, this one is more complete~

I posted the original exploit and was warned 1 week later...T_T

Fortunately, Green Dam is not likely to be mandatory install until today. It` a joke, just a joke ;-)</description>
		<content:encoded><![CDATA[<p>Wow, this one is more complete~</p>
<p>I posted the original exploit and was warned 1 week later&#8230;T_T</p>
<p>Fortunately, Green Dam is not likely to be mandatory install until today. It` a joke, just a joke ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Draper L. Kauffman &#187; Blog Archive &#187; SQL slammer (computer worm)</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1060</link>
		<dc:creator>Draper L. Kauffman &#187; Blog Archive &#187; SQL slammer (computer worm)</dc:creator>
		<pubDate>Wed, 08 Jul 2009 09:03:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1060</guid>
		<description>[...] Recognize-Security &#124; Green Dam URL Processing Buffer Overflow &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Recognize-Security | Green Dam URL Processing Buffer Overflow &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1053</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Sun, 05 Jul 2009 13:45:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1053</guid>
		<description>@spdr Thanks bro&#039;!
A fully working exploit will be posted soon.</description>
		<content:encoded><![CDATA[<p>@spdr Thanks bro&#8217;!<br />
A fully working exploit will be posted soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: spdr</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1047</link>
		<dc:creator>spdr</dc:creator>
		<pubDate>Thu, 02 Jul 2009 01:20:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1047</guid>
		<description>Hey, GJ on the vlc bug ;-) started releasing bugs recently ?</description>
		<content:encoded><![CDATA[<p>Hey, GJ on the vlc bug ;-) started releasing bugs recently ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SecureWorks: Green-Dam-Software enth?lt unsicheren und schlampigen Code - Security &#124; News &#124; ZDNet.de</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1036</link>
		<dc:creator>SecureWorks: Green-Dam-Software enth?lt unsicheren und schlampigen Code - Security &#124; News &#124; ZDNet.de</dc:creator>
		<pubDate>Fri, 26 Jun 2009 08:05:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1036</guid>
		<description>[...] Windows XP SP3 sowie IE7 und Windows Vista SP1 getestet&quot;, schreibt der Sicherheitsforscher in einem Blogeintrag.    .story .element .tags { color: #666666; font-size: 11px; vertical-align: middle; }    Tags: [...]</description>
		<content:encoded><![CDATA[<p>[...] Windows XP SP3 sowie IE7 und Windows Vista SP1 getestet&#8221;, schreibt der Sicherheitsforscher in einem Blogeintrag.    .story .element .tags { color: #666666; font-size: 11px; vertical-align: middle; }    Tags: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Malware Analysis &#38; Diagnostic</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1034</link>
		<dc:creator>Malware Analysis &#38; Diagnostic</dc:creator>
		<pubDate>Wed, 24 Jun 2009 17:28:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1034</guid>
		<description>&lt;strong&gt;Le logiciel de filtrage pornographique du gouvernement chinois est vuln?rable...&lt;/strong&gt;

La France avec ses ~65 millions d&#039;habitants compte ~33 millions d&#039;internautes. Derni?rement, la loi aux multiples noms HADOPI, LCI, OLIVENNES... a ?t? s?rieusement perturb?e par la d?cision (n° 2009-580)&#160; du Conseil Constitutionnel ; les ...</description>
		<content:encoded><![CDATA[<p><strong>Le logiciel de filtrage pornographique du gouvernement chinois est vuln?rable&#8230;</strong></p>
<p>La France avec ses ~65 millions d&#8217;habitants compte ~33 millions d&#8217;internautes. Derni?rement, la loi aux multiples noms HADOPI, LCI, OLIVENNES&#8230; a ?t? s?rieusement perturb?e par la d?cision (n° 2009-580)&nbsp; du Conseil Constitutionnel ; les &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Remote code execution exploit for Green Dam in the wild &#124; Zero Day &#124; ZDNet.com</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1032</link>
		<dc:creator>Remote code execution exploit for Green Dam in the wild &#124; Zero Day &#124; ZDNet.com</dc:creator>
		<pubDate>Wed, 24 Jun 2009 14:52:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1032</guid>
		<description>[...] However, not only is the latest Green Dam v3.17 version still vulnerable to remotely exploitable flaws, but also, for over a week now a working zero day exploit (Exploit.GreenDam!IK; W32/GreenDam.A) has been circulating in the wild. [...]</description>
		<content:encoded><![CDATA[<p>[...] However, not only is the latest Green Dam v3.17 version still vulnerable to remotely exploitable flaws, but also, for over a week now a working zero day exploit (Exploit.GreenDam!IK; W32/GreenDam.A) has been circulating in the wild. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1029</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Tue, 23 Jun 2009 00:13:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1029</guid>
		<description>The software was silently patched the vendor on June 13. Still version 3.17 and with no public notice.
But, the vulnerability can be leveraged in different ways, see - http://www.cse.umich.edu/~jhalderm/pub/gd/#add1

The .NET binary is loaded to 0x24240000 because the return address is overwritten with $$$$, == 0x24242424.</description>
		<content:encoded><![CDATA[<p>The software was silently patched the vendor on June 13. Still version 3.17 and with no public notice.<br />
But, the vulnerability can be leveraged in different ways, see &#8211; <a href="http://www.cse.umich.edu/~jhalderm/pub/gd/#add1" rel="nofollow">http://www.cse.umich.edu/~jhalderm/pub/gd/#add1</a></p>
<p>The .NET binary is loaded to 0&#215;24240000 because the return address is overwritten with $$$$, == 0&#215;24242424.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spk</title>
		<link>http://www.rec-sec.com/2009/06/16/green-dam-url-overflow-exploit/comment-page-1/#comment-1027</link>
		<dc:creator>Spk</dc:creator>
		<pubDate>Mon, 22 Jun 2009 18:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=678#comment-1027</guid>
		<description>i downloaded greendam from lssw365 site (version 3.17) and can&#039;t reproduce the bug, no access violation or any kind of exception occurs.
and another question, in the exploit, why the .net binary loads to image base 0x24240000 ?</description>
		<content:encoded><![CDATA[<p>i downloaded greendam from lssw365 site (version 3.17) and can&#8217;t reproduce the bug, no access violation or any kind of exception occurs.<br />
and another question, in the exploit, why the .net binary loads to image base 0&#215;24240000 ?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
