First, open excel, and attach to it using WinDBG Figure WinDBG_Attaching_to_Excel.
Tainted data will remain for long time, also increasing the explosion problem (to delete the tracking over a data, it is required that this data receives an uncontrolled value, or is deallocated somehow).
As previously explained, the debugger will LoadLibrary the extension dll and then will use the GetProcAddress to find the entry point.This is a requirement to later determine the exploitability.Now everything is ready, and you will have the taint analysis of the instructions you are interested of, related to the range of memory you just specified.2.2 - Backward Taint Analysis Backward Taint Analysis is a reverse approach to the natural taint analysis flow.Some of the functionalities supported: - Get current thread/process information - Read/Write memory - Symbol/type lookup To call the extension functions, one need to first created the debug interface objects and then call the interface exposed by these objects.The problem is that the only available solution to analyze such crashes are provided by Microsoft (named!exploitable or bang exploitable) 34 and are not really useful to create actual exploits or to better understand the problem, but just to give a static classification (exploitable, probably.A data area is 'used' when it is referenced by an operation and is 'defined' when the data is modified.In Piotr's paper, he explains the Virtual Code Integration (or Dynamic Binary Rewriting) approach.The project is been open-sourced here, so I expect to receive patches.This is a great initiative and contributed a lot for the growing number of cooperation between researchers and the software industry (since now the vendors can at least classify the exploitability of each reported vulnerability).Issues : Get tar.This tool aims at solving the challenge of heap tests for embedded Linux architectures using ARM (much less advanced then the Valgrind Memcheck plugin, altought the only option for ARM as far as the author is aware).
"Triaging Bugs with Dynamic Dataflow Analysis".

