Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: May 21, 2009
Lauren Gerber
2
Vote
0

Buffer Overflow And DDOS Vulnerability In BreakPOint Software Hex Workshop

 

It has happened yet again, yes you have guessed it, another vulnerability has hit our fabulous online world. This time the vulnerabilities pertain to the BreakPoint Software Hex Workshop. Multiple vulnerabilities have been reported with the inclusion of a buffer overflow as well as DDOS vulnerability.

The question that may be asked is: What is BreakPoint Software? BreakPoint Software is a company that specifically designs quality development tools geared towards software professionals. The company came into existence in the year 1995 and since then has developed top quality software orientated for developer professionals. The motto that they came up with when they first started out was:"For Developers by Developers".Breakpoint_software..jpg

The problem is that with this specific kind of buffer overflow vulnerability, malicious individuals are able to cause a denial of service attack. This is not the only thing that malicious individuals are able to do with this vulnerability, in addition to this denial of service attack, they are also able to execute arbitrary code. This arbitrary code can be executed with the use of a long mapping reference in a specific colour mapping file. (.cmap) 

With regard to the colour mapping file and local buffer overflow, the following may work, but needs some more attention:

Just import (enc.cmap) From (Tools>Color Mapping) And See What Happen ^_^
# I Think it's Easy To Exploit but need some work *_^
chars = "A"*4500
foot = "\x20\x3D\x20\x52\x47\x42\x28\x30\x2C\x20\x30\x2C\x20\x30\x29\x2C\x20\x52\x47\x42\x28\x31\x36\x30\x2C\x20\x31\x36\x30\x2C\x20\x31\x36\x30\x29"
file=open('enc.cmap','w+')
file.write("\x22"+chars+"\x22"+foot)
file.close()Workshop.jpg

It is vital to take into account that this particular vulnerability in BreakPoint software Hex Workshop pertains to version 5.1.4.It is also needs to be taken into account that specific user assisted attackers are able to obtain administrator access if this is their desire. A specific service can also be broken up with the help of these multiple vulnerabilities. It can thus be quoted in conclusion: If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. - White House Cyber security Advisor, Richard Clarke

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 17, 2010
March 17, 2010
Found this list of godaddy domain name coupons, I got a domain for my dog - ha $6.91 Domain... more..
March 17, 2010
Three guys were having a beer in a bar in London. They were all relative newly-weds and they were talking... more..
more comments..
rss
Home > Computer Security > Buffer Overflow And DDOS Vulnerability In BreakPOint Software Hex Workshop