BugTraq
BoF in Windows 2000: ddeshare.exe Nov 09 2004 02:24AM
Jack C (jack crepinc com) (2 replies)
Re: BoF in Windows 2000: ddeshare.exe Nov 09 2004 07:59PM
Valdis Kletnieks vt edu (1 replies)
Re: BoF in Windows 2000: ddeshare.exe Nov 10 2004 07:19PM
J. S. Connell (ankh canuck gen nz)
On Tue, 9 Nov 2004 Valdis.Kletnieks (at) vt (dot) edu [email concealed] wrote:

> Ah, but what if the 2 trailing B's are replaced by 2 Unicode chars that
> together take up 4 bytes? ;)

Or we can realize that in Windows NT, XP, and above, all "characters" are
two-byte-wide UNICODE characters, and that we're not seeing "[NULs]
inserted between characters" but simply UNICODE characters with very low
ordinals.

It's probably worth pointing out that a large fraction of the 16-bit
UNICODE space is taken up with Chinese, Japanese, and Korean characters.

In fact, UNICODE codepoint 0x9090 happens to be the Chinese character for
[li3], "winding" or "meandering". Chinese poetry shellcode, anybody?

--Jeffrey

[ reply ]
Re: BoF in Windows 2000: ddeshare.exe Nov 09 2004 04:11PM
Berend-Jan Wever (skylined edup tudelft nl)


 

Privacy Statement
Copyright 2010, SecurityFocus