Re: [Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-12-16 Thread Yuhong Bao
http://www.mischel.com/winhelp/whdll1.html Date: Mon, 29 Oct 2012 10:02:03 -0500 From: richard.k.mi...@googlemail.com To: gynv...@coldwind.pl CC: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Microsoft Windows Help program (WinHlp32

Re: [Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-10-30 Thread Richard Miles
I was looking and appear that this bug was fixed a long time ago at ms, also windows help (.hlp) do not appear to be automatic opened in windows vista and later. On Sat, Oct 27, 2012 at 2:38 PM, Gynvael Coldwind gynv...@coldwind.plwrote: Hi Kaveh, Mario has a point. Why do you care about any

Re: [Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-10-30 Thread Peter Ferrie
I was looking and appear that this bug was fixed a long time ago at ms, No, the bugs remain. However... also windows help (.hlp) do not appear to be automatic opened in windows vista and later. That's the point - hlp is such an unsafe file format that the winhlp32.exe was *removed* from

Re: [Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-10-29 Thread Richard Miles
Where can I find more details or a tool to automate this process? I would like to test this HLP files being used to execute code. On Sat, Oct 27, 2012 at 2:38 PM, Gynvael Coldwind gynv...@coldwind.plwrote: Hi Kaveh, Mario has a point. Why do you care about any bug in winhlp if by design you

[Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-10-27 Thread kaveh ghaemmaghami
Hello list! I want to warn you about Microsoft Windows Help program (WinHlp32.exe) memory corruption Best Regards Kaveh Ghaemmaghami aka (coolkaveh) -

Re: [Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-10-27 Thread Gynvael Coldwind
Hi Kaveh, Mario has a point. Why do you care about any bug in winhlp if by design you can embed a DLL file in the .hlp file and run arbitrary code? See e.g. Wikipedia http://en.wikipedia.org/wiki/WinHelp#WinHelp_appearance_and_features: A rather security critical feature is that one can also