<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Vreugdenhil Research &#187; exploits</title>
	<atom:link href="http://vreugdenhilresearch.nl/topics/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://vreugdenhilresearch.nl</link>
	<description>Research, Vulnerabilities and Exploits</description>
	<lastBuildDate>Fri, 17 Jun 2011 16:59:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PoC for MS10-071</title>
		<link>http://vreugdenhilresearch.nl/poc-for-ms10-071/</link>
		<comments>http://vreugdenhilresearch.nl/poc-for-ms10-071/#comments</comments>
		<pubDate>Tue, 26 Apr 2011 16:53:36 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://vreugdenhilresearch.nl/?p=216</guid>
		<description><![CDATA[Here is a PoC for MS10-071 Its nice vulnerability that allows for information disclosure and triggering a use-after-free. The PoC should be able to fetch the address for mshtml.dll and then trigger a use-after-free ending the execution at eip 0&#215;41414141 or referencing a vftable at 0&#215;41414141 I forgot what it did. Anyways, no explanations only [...]]]></description>
		<wfw:commentRss>http://vreugdenhilresearch.nl/poc-for-ms10-071/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Java midi parse vulnerabilities</title>
		<link>http://vreugdenhilresearch.nl/java-midi-parse-vulnerabilities/</link>
		<comments>http://vreugdenhilresearch.nl/java-midi-parse-vulnerabilities/#comments</comments>
		<pubDate>Fri, 21 May 2010 14:09:49 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://vreugdenhilresearch.nl/?p=80</guid>
		<description><![CDATA[Index Introduction Basic information on Java Java and sound files Null byte write to stack User supplied function pointer call Heap overflow Links Introduction A while back I found some vulnerabilities in the way java handles certain audio files. Those problems were fixed in Java update 19, and since anyone who did not yet install [...]]]></description>
		<wfw:commentRss>http://vreugdenhilresearch.nl/java-midi-parse-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Old bugs: YaBB</title>
		<link>http://vreugdenhilresearch.nl/old-bugs-yabb/</link>
		<comments>http://vreugdenhilresearch.nl/old-bugs-yabb/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 16:41:51 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[POC]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://vreugdenhilresearch.nl/?p=63</guid>
		<description><![CDATA[I decided to write up on some old and funny bugs I found a while back. Starting today with &#8216;remote&#8217; code execution in YaBB version 2.2 the problem is fixed in 2.4 (or so it seems at first glance) YaBB (yet another bulletin board) is as the name says a bulletin board. Its written in [...]]]></description>
		<wfw:commentRss>http://vreugdenhilresearch.nl/old-bugs-yabb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ICQ Exploit CVE-2006-5650</title>
		<link>http://vreugdenhilresearch.nl/icq-exploit-cve-2006-5650/</link>
		<comments>http://vreugdenhilresearch.nl/icq-exploit-cve-2006-5650/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 15:54:02 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[CVE-2006-5650]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[ICQ]]></category>
		<category><![CDATA[POC]]></category>

		<guid isPermaLink="false">http://vreugdenhilresearch.nl/?p=26</guid>
		<description><![CDATA[I'll kick off with imho one of my more interresting findings. Its not interresting due to the nature of the vulnerability, but due to the possible impact. It was quite some time ago already, back in the summer of 2006 when I was looking into COM objects that came installed with ICQ. If you're unfamiliair with COM objects and how that 'sneak' in with program installations, I suggest you read this article. Anyway, installing ICQ added a few COM objects that were accesible as ActiveX Objects in IE6 without warning. Most of them were a bit boring, but there was a nice design error in one of them]]></description>
		<wfw:commentRss>http://vreugdenhilresearch.nl/icq-exploit-cve-2006-5650/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

