Results 1 to 4 of 4

Thread: Spybot S&D and lack of ASLR support

  1. #1
    Member
    Join Date
    Jan 2009
    Posts
    78

    Default Spybot S&D and lack of ASLR support

    I was checking Spybot S&D in Process Explorer, and it lacks ASLR support. This obviously includes the dll file SDHelper.dll, which is loaded to IE and Explorer.

    Is there any technical reason why Spybot lacks ASLR?


    thanks

  2. #2
    Junior Member
    Join Date
    Feb 2011
    Posts
    3

    Default

    No reply from Safer-Networking?
    Do you know that you're making the system vulnerable by loading DLL's that don't support ASLR into processes that are exploited like explorer.exe and browsers?
    http://blog.didierstevens.com/2011/01/17/quickpost-it-does-no-harm-or-does-it/
    http://www.scriptjunkie.us/2011/06/bypassing-dep-aslr-in-browser-exploits-with-mcafee-symantec/
    I did a quick test with the latest beta and checked IE and explorer.exe, the DLL in explorer.exe doesn't support ASLR.

  3. #3
    Senior Member ght1's Avatar
    Join Date
    Apr 2008
    Posts
    210

    Default

    Quote Originally Posted by BoerenkoolMetWorst View Post
    No reply from Safer-Networking?
    What's the news?

  4. #4
    Senior Member
    Join Date
    May 2010
    Posts
    114

    Lightbulb

    Is it just that Spybot doesn't use ASLR by default (like most apps) or that it (like Safari) fails to work when EMET or a similar tool is used to force Spybot to use ASLR?

    Also it might be a good idea to see whether the beta of Spybot 2 does support ASLR; perhaps it was only added in this time because of increased support across the operating systems in the user-base.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •