<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Quickpost: Another Funny Vista Trick with ASLR</title>
	<atom:link href="http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/</link>
	<description>(blog 'DidierStevens)</description>
	<pubDate>Tue, 06 Jan 2009 08:09:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Luciano Aibar</title>
		<link>http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-31207</link>
		<dc:creator>Luciano Aibar</dc:creator>
		<pubDate>Mon, 21 Apr 2008 07:23:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-31207</guid>
		<description>Disabling ASLR is good for debugging, let's say debugging windows DLLs (for ex. cracking).

I would suggest to create a simple DOS program that changes the bit.. let's say "no_aslr.exe"
Boot from a USB Pen Drive with NTFS4DOS 1.9 Personal (it's free and allows u read/write NTFS part.)
Use "no_aslr.exe file.dll" with any file.
Modifying files while in DOS do not affect the security permissions.</description>
		<content:encoded><![CDATA[<p>Disabling ASLR is good for debugging, let&#8217;s say debugging windows DLLs (for ex. cracking).</p>
<p>I would suggest to create a simple DOS program that changes the bit.. let&#8217;s say &#8220;no_aslr.exe&#8221;<br />
Boot from a USB Pen Drive with NTFS4DOS 1.9 Personal (it&#8217;s free and allows u read/write NTFS part.)<br />
Use &#8220;no_aslr.exe file.dll&#8221; with any file.<br />
Modifying files while in DOS do not affect the security permissions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KJK::Hyperion</title>
		<link>http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-21183</link>
		<dc:creator>KJK::Hyperion</dc:creator>
		<pubDate>Thu, 29 Nov 2007 10:22:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-21183</guid>
		<description>I'm sorry, I had a bad day.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry, I had a bad day.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-20862</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Tue, 27 Nov 2007 08:58:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-20862</guid>
		<description>Is this part of your therapy?</description>
		<content:encoded><![CDATA[<p>Is this part of your therapy?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KJK::Hyperion</title>
		<link>http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-20762</link>
		<dc:creator>KJK::Hyperion</dc:creator>
		<pubDate>Mon, 26 Nov 2007 13:38:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-20762</guid>
		<description>&#62;I didn’t think it would, because you’re only touching the PE Header, which is not protected by the Authenticode signature.

That's the most retarded thing I read in a long time. Of course the signature covers the header, moron. Hey, what do I know, the PE header "only" contains such irrelevant, purely advisory fields as the entry point offset, and it would take all of 10 minutes to check that flipping the DLL characteristics bit does indeed invalidate the signature anyway. BUT WHAT THE BLEEP DO I KNOW, I'm not a card-carrying IT Security Professional  !

The sheer stupidity of certain statements just jumps at your face, screaming</description>
		<content:encoded><![CDATA[<p>&gt;I didn’t think it would, because you’re only touching the PE Header, which is not protected by the Authenticode signature.</p>
<p>That&#8217;s the most retarded thing I read in a long time. Of course the signature covers the header, moron. Hey, what do I know, the PE header &#8220;only&#8221; contains such irrelevant, purely advisory fields as the entry point offset, and it would take all of 10 minutes to check that flipping the DLL characteristics bit does indeed invalidate the signature anyway. BUT WHAT THE BLEEP DO I KNOW, I&#8217;m not a card-carrying IT Security Professional  !</p>
<p>The sheer stupidity of certain statements just jumps at your face, screaming</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juanillo</title>
		<link>http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-20628</link>
		<dc:creator>Juanillo</dc:creator>
		<pubDate>Sun, 25 Nov 2007 14:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/11/20/quickpost-another-funny-vista-trick-with-aslr/#comment-20628</guid>
		<description>Hi didier.
Yoy have an excelent blog!
Any executable can decide to participate in ASLR by setting bit 0x40 in the field DLL CHARACTERISTICS. You have a document write by the symantec team submitted in the blackhat 2007.
The thing is that any user with admin privileges, can disable this feature, making it easier an attack code execution for the executable.
Its a funny trick!!

http://www.blackhat.com/presentations/bh-dc-07/Whitehouse/Paper/bh-dc-07-Whitehouse-WP.pdf

Sorry for my English.... Spanglish its better for me.... :)
regards</description>
		<content:encoded><![CDATA[<p>Hi didier.<br />
Yoy have an excelent blog!<br />
Any executable can decide to participate in ASLR by setting bit 0&#215;40 in the field DLL CHARACTERISTICS. You have a document write by the symantec team submitted in the blackhat 2007.<br />
The thing is that any user with admin privileges, can disable this feature, making it easier an attack code execution for the executable.<br />
Its a funny trick!!</p>
<p><a href="http://www.blackhat.com/presentations/bh-dc-07/Whitehouse/Paper/bh-dc-07-Whitehouse-WP.pdf" rel="nofollow">http://www.blackhat.com/presentations/bh-dc-07/Whitehouse/Paper/bh-dc-07-Whitehouse-WP.pdf</a></p>
<p>Sorry for my English&#8230;. Spanglish its better for me&#8230;. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
regards</p>
]]></content:encoded>
	</item>
</channel>
</rss>
