<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft !exploitable Extension Review</title>
	<atom:link href="http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/</link>
	<description></description>
	<lastBuildDate>Wed, 10 Mar 2010 01:49:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Opinimand</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-456</link>
		<dc:creator>Opinimand</dc:creator>
		<pubDate>Sun, 07 Mar 2010 04:24:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-456</guid>
		<description>thank!</description>
		<content:encoded><![CDATA[<p>thank!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pooredize</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-442</link>
		<dc:creator>Pooredize</dc:creator>
		<pubDate>Mon, 18 Jan 2010 09:59:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-442</guid>
		<description>блин...писал-писал, а сообщение не отправилось и не сохранилось :) вообщем блог понравился. админу удачи в развитии.</description>
		<content:encoded><![CDATA[<p>блин&#8230;писал-писал, а сообщение не отправилось и не сохранилось <img src='http://www.snoop-security.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  вообщем блог понравился. админу удачи в развитии.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pooredize</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-441</link>
		<dc:creator>Pooredize</dc:creator>
		<pubDate>Sat, 16 Jan 2010 08:42:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-441</guid>
		<description>А мне блог понравился</description>
		<content:encoded><![CDATA[<p>А мне блог понравился</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blog4liferu</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-439</link>
		<dc:creator>blog4liferu</dc:creator>
		<pubDate>Tue, 12 Jan 2010 19:05:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-439</guid>
		<description>yes, partseoru. +1</description>
		<content:encoded><![CDATA[<p>yes, partseoru. +1</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: partseoru</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-433</link>
		<dc:creator>partseoru</dc:creator>
		<pubDate>Sat, 02 Jan 2010 03:03:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-433</guid>
		<description>Я извиняюсь, но, по-моему, Вы не правы. Я уверен. Давайте обсудим.
--
English : I&#039;m sorry, but, in my opinion, you&#039;re wrong. I&#039;m sure. Let&#039;s discuss.
/Snake</description>
		<content:encoded><![CDATA[<p>Я извиняюсь, но, по-моему, Вы не правы. Я уверен. Давайте обсудим.<br />
&#8211;<br />
English : I&#8217;m sorry, but, in my opinion, you&#8217;re wrong. I&#8217;m sure. Let&#8217;s discuss.<br />
/Snake</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zashkaser</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-185</link>
		<dc:creator>Zashkaser</dc:creator>
		<pubDate>Wed, 05 Aug 2009 17:37:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-185</guid>
		<description>thanks for the catch. I’ll get in there and fix it….</description>
		<content:encoded><![CDATA[<p>thanks for the catch. I’ll get in there and fix it….</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sCORPINo</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-145</link>
		<dc:creator>sCORPINo</dc:creator>
		<pubDate>Sun, 28 Jun 2009 23:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-145</guid>
		<description>@Mario
Thanks for reading this review and commenting on :-)
yep, DEP have to be reported as Exploitable, and i encourage MS guys, that accepted their mitigation can be bypassed(as mentioned in their plugin result).

yes, this plugin can be great when you got a bunch of crashes from a fuzzing session and want to clarify security bugs from other bugs to focus on them.
thanks for your great comments again ;-)</description>
		<content:encoded><![CDATA[<p>@Mario<br />
Thanks for reading this review and commenting on <img src='http://www.snoop-security.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /><br />
yep, DEP have to be reported as Exploitable, and i encourage MS guys, that accepted their mitigation can be bypassed(as mentioned in their plugin result).</p>
<p>yes, this plugin can be great when you got a bunch of crashes from a fuzzing session and want to clarify security bugs from other bugs to focus on them.<br />
thanks for your great comments again <img src='http://www.snoop-security.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mario Vilas</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-144</link>
		<dc:creator>Mario Vilas</dc:creator>
		<pubDate>Sun, 28 Jun 2009 19:10:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-144</guid>
		<description>Good review :)

I&#039;ve got some comments to add to it:

DEP access violations have to be reported as exploitable, because not all hardwares and not all Windows installations support or enable DEP.

Breakpoints may or may not be related to security bugs. For example, when the heap is in debug mode, a breakpoint will be hit whenever a heap buffer overflow is detected.

Also, I believe you&#039;ll get a better result with the format string poc if you use %n rather than %x. That way you&#039;ll get an access violation when writing rather than reading.

All in all I think it&#039;s a good tool to couple with a fuzzer. It can filter out quite a few harmless crashes. Then again, of course, it can&#039;t replace a human analysis, but I don&#039;t think it&#039;s meant to.

Nice post, keep up the good work! :)</description>
		<content:encoded><![CDATA[<p>Good review <img src='http://www.snoop-security.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I&#8217;ve got some comments to add to it:</p>
<p>DEP access violations have to be reported as exploitable, because not all hardwares and not all Windows installations support or enable DEP.</p>
<p>Breakpoints may or may not be related to security bugs. For example, when the heap is in debug mode, a breakpoint will be hit whenever a heap buffer overflow is detected.</p>
<p>Also, I believe you&#8217;ll get a better result with the format string poc if you use %n rather than %x. That way you&#8217;ll get an access violation when writing rather than reading.</p>
<p>All in all I think it&#8217;s a good tool to couple with a fuzzer. It can filter out quite a few harmless crashes. Then again, of course, it can&#8217;t replace a human analysis, but I don&#8217;t think it&#8217;s meant to.</p>
<p>Nice post, keep up the good work! <img src='http://www.snoop-security.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Max</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-139</link>
		<dc:creator>Max</dc:creator>
		<pubDate>Sun, 07 Jun 2009 18:41:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-139</guid>
		<description>Interisting post, keep work</description>
		<content:encoded><![CDATA[<p>Interisting post, keep work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hamid.K</title>
		<link>http://www.snoop-security.com/blog/index.php/2009/03/microsoft-exploitable-extension-review/comment-page-1/#comment-30</link>
		<dc:creator>Hamid.K</dc:creator>
		<pubDate>Wed, 01 Apr 2009 21:48:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.snoop-security.com/blog/?p=6#comment-30</guid>
		<description>Good post , :)
keep the good work.

---------------------------------------------------------------------
&lt;strong&gt;sCORPINo&lt;/strong&gt;:
Thanks for your comment.</description>
		<content:encoded><![CDATA[<p>Good post , <img src='http://www.snoop-security.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
keep the good work.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
<strong>sCORPINo</strong>:<br />
Thanks for your comment.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
