четверг, 13 декабря 2012 г.

Sandboxie ProbeForWrite fail

Main article about it here:
Sandboxie Exploitation 
After some research in sandboxie driver i am found simple vulnerability.
For example in x86 driver(bug exist on both arch model x86 and x64)
See picture:

If DelayLoadDll structure exist function must write to usermode buffer file path
Show in next picture:

