Re: [FD] iis cgi 0day

2014-04-18 Thread YiFei Yang
rote: > > Am 16.04.2014 08:39, schrieb Davide Davini: > > > YiFei Yang wrote: > > >> It is a bug affecting IIS4/5 using CGI on Windows NT/2000. Microsoft > is > > >> aware of it and won't fix it. > > > > > > Is there any workaround th

Re: [FD] FW: dve bypass dep+aslr+emet+cfi

2014-04-11 Thread YiFei Yang
Most people here don't read Chinese, so please, post in English, and link only to English materials. And for those who don't read Chinese, this post doesn't worth reading at all, it's highly likely to be copy-pasted from several Weibo(Twitter in China). I, as a native Chinese speaker, can't figur

Re: [FD] iis cgi 0day

2014-04-10 Thread YiFei Yang
le. The information above is translated from the original post, I haven't tried the exploit yet, but I will try that when I have some time to spare. > > Thanks. > > > On Thu, Apr 10, 2014 at 2:19 AM, YiFei Yang wrote: >> >> So, for you who doesn't read Chi

Re: [FD] iis cgi 0day

2014-04-10 Thread YiFei Yang
So, for you who doesn't read Chinese, here's the brief idea of the original post. It is a bug affecting IIS4/5 using CGI on Windows NT/2000. Microsoft is aware of it and won't fix it. The discovery of the bug was back in year 2011. By exploiting this bug, the attacker can set arbitrary environme