Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: May 21, 2009
Lauren Gerber
2
Vote
0

Buffer Overflow And DDOS Vulnerability In BreakPOint Software Hex Workshop

 

It has happened yet again, yes you have guessed it, another vulnerability has hit our fabulous online world. This time the vulnerabilities pertain to the BreakPoint Software Hex Workshop. Multiple vulnerabilities have been reported with the inclusion of a buffer overflow as well as DDOS vulnerability.

The question that may be asked is: What is BreakPoint Software? BreakPoint Software is a company that specifically designs quality development tools geared towards software professionals. The company came into existence in the year 1995 and since then has developed top quality software orientated for developer professionals. The motto that they came up with when they first started out was:"For Developers by Developers".Breakpoint_software..jpg

The problem is that with this specific kind of buffer overflow vulnerability, malicious individuals are able to cause a denial of service attack. This is not the only thing that malicious individuals are able to do with this vulnerability, in addition to this denial of service attack, they are also able to execute arbitrary code. This arbitrary code can be executed with the use of a long mapping reference in a specific colour mapping file. (.cmap) 

With regard to the colour mapping file and local buffer overflow, the following may work, but needs some more attention:

Just import (enc.cmap) From (Tools>Color Mapping) And See What Happen ^_^
# I Think it's Easy To Exploit but need some work *_^
chars = "A"*4500
foot = "\x20\x3D\x20\x52\x47\x42\x28\x30\x2C\x20\x30\x2C\x20\x30\x29\x2C\x20\x52\x47\x42\x28\x31\x36\x30\x2C\x20\x31\x36\x30\x2C\x20\x31\x36\x30\x29"
file=open('enc.cmap','w+')
file.write("\x22"+chars+"\x22"+foot)
file.close()Workshop.jpg

It is vital to take into account that this particular vulnerability in BreakPoint software Hex Workshop pertains to version 5.1.4.It is also needs to be taken into account that specific user assisted attackers are able to obtain administrator access if this is their desire. A specific service can also be broken up with the help of these multiple vulnerabilities. It can thus be quoted in conclusion: If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. - White House Cyber security Advisor, Richard Clarke

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Download (Spyware/Trojan Detection), SCAN, BLOCK Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

February 9, 2010
I had the same problem with that Antivirus soft ***. All I did was reboot the computer to safemode... more..
February 8, 2010
Brian xavier- what is the support option you speak of? I just got it yesterday 2/12 since you had it... more..
February 8, 2010
Zlob is one of the most common types of trojan programs used to attack windows these days. In a typical... more..
more comments..
rss
Home > Computer Security > Buffer Overflow And DDOS Vulnerability In BreakPOint Software Hex Workshop