RE: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day

2006-12-22 Thread Michele Cicciotti
Holy mackerel! Instances of this bug date back to 1999! Different bug. That appears to be a trivial exhaustion of CSRSS worker threads through indiscriminate calls to MessageBox+MB_SERVICE_NOTIFICATION, which causes a DoS as no threads are available to serve kernel-mode requests from win32k,

RE: [Full-disclosure] Fun with event logs (semi-offtopic)

2006-12-21 Thread Michele Cicciotti
There is interesting thing with event logging on Windows. The only security aspect of it is event log record tampering and performance degradation, but it may become sensitive is some 3rd party software is used for automated event log analysis. I doubt this. The event logs don't

RE: Re[2]: [Full-disclosure] Fun with event logs (semi-offtopic)

2006-12-21 Thread Michele Cicciotti
Yes, probably this bug only affects event viewer itself. I don't understand how and why Microsoft achieved this effect in event viewer, which is, by the way, security tool, and if it's hard for different vendor to make same mistake. For what it's worth, the updated viewer