<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; windows-media-player-exploit</title>
	<atom:link href="http://www.darknet.org.uk/tag/windows-media-player-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Serious Exploit in Windows Media Player (WMP)</title>
		<link>http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/</link>
		<comments>http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/#comments</comments>
		<pubDate>Fri, 05 Jan 2007 04:30:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-media-player]]></category>
		<category><![CDATA[windows-media-player-exploit]]></category>
		<category><![CDATA[wmp-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/</guid>
		<description><![CDATA[Oh look! Another 0-day in Windows&#8230;this time in Media Player, there was a few in Word lately and the latest thing that just hit is an XSS flaw in PDF files online. I&#8217;ll report more on those later. The Windows Media Player library WMVCORE.DLL contains a potentially exploitable heap buffer overflow in its handling of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Oh look! Another 0-day in Windows&#8230;this time in Media Player, there was a few in Word lately and the latest thing that just hit is an XSS flaw in PDF files online.</p>
<p>I&#8217;ll report more on those later.</p>
<blockquote><p>The Windows Media Player library WMVCORE.DLL contains a potentially exploitable heap buffer overflow in its handling of &#8220;REF HREF&#8221; URLs within ASX files. If the URL contains an unrecognized protocol (only &#8220;file&#8221;, &#8220;ftp&#8221;, &#8220;http&#8221;, &#8220;https&#8221;, &#8220;mms&#8221;, &#8220;mmst&#8221;, &#8220;mmsu&#8221;, &#8220;rtsp&#8221;, &#8220;rtspt&#8221;, and &#8220;rtspu&#8221; appear to be recognized), the function at 7D7A8F27 in WMVCORE.DLL version 9.0.0.3250, and at 086E586E in WMVCORE.DLL version 10.0.0.3802, will create a copy of the string in which the protocol is replaced with &#8220;mms&#8221;. A heap buffer is allocated, the string &#8220;mms&#8221; is copied into it, and then everything after and including &#8220;://&#8221; in the &#8220;REF HREF&#8221; URL is concatenated using wcsncat.</p></blockquote>
<p>So what out what you are streaming..please! Or alternatively use something decent like Winamp.</p>
<blockquote><p>Unfortunately, the heap buffer for the new &#8220;mms&#8221; URL is allocated to the size of the &#8220;REF HREF&#8221; URL, and even more unfortunately, the length of the input string being passed to wcsncat is supplied as the character count, effectively causing wcsncat to behave identically to wcscat. As a result, a two- or four-byte heap overflow is possible if the &#8220;REF HREF&#8221; URL features a protocol shorter than three characters (the length of &#8220;mms&#8221;).</p>
<p>Single-letter protocols (such as &#8220;a://&#8221;) are rejected, but this restriction can be circumvented by encoding the protocol (&#8220;%61://&#8221;), thereby making a four-byte overflow possible.</p>
<p>Exploitability due to the corruption of the adjacent heap block&#8217;s header is assumed likely but research is ongoing.</p></blockquote>
<p>As far as I know there&#8217;s no current exploit for this, but it is a possibility.</p>
<p></p>
<p>Source: <a href="http://research.eeye.com/html/alerts/zeroday/20061122.html">eEye</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Serious+Exploit+in+Windows+Media+Player+%28WMP%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D411+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;t=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/&amp;title=Serious+Exploit+in+Windows+Media+Player+%28WMP%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Fserious-exploit-in-windows-media-player-wmp%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/serious-exploit-in-windows-media-player-wmp/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

