From Patch to Exploit
February 13th, 2008
If you are at all interested in how exploits are created by reversing patches, check out HD Moore's post over at BreakingPoint System Strike Center: Exploiting IIS via HTMLEncode (MS08-006).
It is a step-by-step walk-through of how the vulnerability was located in the patch, the analysis applied to determine the flaw and finally how the exploit was developed. An informative and interesting read if you are into that sort of thing.
Posted by gfleischer on 2008/02/13 at 23:17 in Exploits