Even "EMET" is not infallible!!

Status
Not open for further replies.

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
Dec 30, 2012
4,806
1
37,077
5,788
58
Sydney
money-680x400.jpg

LATEST MICROSOFT $100,000 BOUNTY WINNER BYPASSES ASLR, DEP MITIGATIONS

Yang Yu is no stranger to writing mitigation bypasses for Microsoft Windows products.
A year ago at the CanSecWest conference in Vancouver, the 35-year-old security researcher from Beijing did an extensive presentation on bypassing Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP) without return-oriented programming. ASLR and DEP are memory protection and code execution mitigations native to the Windows operating system.

More
 
Congrats to Yang Yu! Think Microsoft would just hire the guy or at least buck up a little more cash.$100,000 to Microsoft is like me giving a bounty for $10.
 
  • Like
Reactions: Venustus and Ink
I like this guys quote: “I think vulnerabilities are like bullets, and mitigation bypass techniques are like guns,” Yu said. “Trying to stop so [many] bullets is never better than destroying the gun.”
 
Status
Not open for further replies.