Hello, sla.ckers!
Those who use Firefox 3.5.3 with FoxTab 1.2.1 and Shockwave Flash 10.0.32.18 may see this kind of thing. To reproduce this you need to OPEN firefox.exe from WinDbg - attaching to already running Firefox doesn't show such thing.
(618.974): Guard page violation - code 80000001 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=056c8000 ebx=00000010 ecx=0013eb28 edx=08010000 esi=08010000 edi=0013eb28
eip=051b8d2a esp=0013e900 ebp=00000003 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00010202
NPSWF32!native_ShockwaveFlash_TCallLabel+0xdd9f4:
051b8d2a 881e mov byte ptr [esi],bl ds:0023:08010000=10
0:000> !exploitable
Exploitability Classification: EXPLOITABLE
Recommended Bug Title: Exploitable - Guard Page Violation starting at NPSWF32!native_ShockwaveFlash_TCallLabel+0x00000000000dd9f4 (Hash=0x00000000.0x00000007)
I'm not quite sure about, cause I only could test it on my machine (Windows XP Pro SP2). But, as far as it is exploitable, what can you say about it?
---------
http://p0deje.blogspot.com