01.02.2014 Views

SBDA “same bug, different app” - Security Assessment

SBDA “same bug, different app” - Security Assessment

SBDA “same bug, different app” - Security Assessment

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>SBDA</strong> – The Conception<br />

• I Wanted To Find A Remote Vulnerability<br />

And it was going to affect IIS<br />

• Six Months Of My Life<br />

Fuzzing, De<strong>bug</strong>ging, Disassembling<br />

• Turned Up<br />

Zilch, Zip, Nada, Nothing<br />

• Take A Step Back<br />

As is usual, the answer comes when you stop thinking of the<br />

question<br />

• The Methodical Approach To Finding Buffer Overflows<br />

The theory was to use existing known attack vectors to<br />

methodically test IIS components<br />

Copyright <strong>Security</strong>-<strong>Assessment</strong>.com 2005

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!