Re: [Full-disclosure] Hikaru




10 pts to the first person using this approach to dlopen for full
arbitrary execution :)

so which is more useful in practice, NX or ASLR?

NX + ASLR + PIE/RANDEXEC ;)

[oh well, someone could argue, not having bug at all.]

BTW, I don't like the statement in the paper which basically considers the
efforts into the deployment of "W^X approaches" a consequence of
understimating ret-into-* (libc/text/code chunks/gadgets) attacks.
W^X just addresses different problems.

PIE and RANDEXEC are the real opponents to those attacks
and it's a bit bad that they are not mentioned at all in the paper.


- twiz

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: VS 2008 Crash (beim Debuggen) durch memcmp?
    ... wir mit Einzelsteps drüber gehen und dann die Memory-Fenster offen haben, ... Mich hat dieser Bug schon einges an Nerven gekostet. ... Manche 20 Minütige wichtige und interessant Debug-Session fand so ihr unrühmliches und ineffektives Ende... ... BTW: Diese Probleme habe ich seit VS-2003 bis einschließlich VS-2008 beobachtet. ...
    (microsoft.public.de.vc)
  • Re: Pocket Pc Bug and Enter key
    ... (and of which the link was out of date, BTW) ... KOOK Pocket Software ... > If you made a search on google with: ... > I want more information on this BUG. ...
    (microsoft.public.pocketpc.developer)
  • Re: Free Pascal 2.2.2 released!
    ... Btw, do you happen to use some odd ball kbd? ... These are not codepage problems! ... If you define a window, and the crt output does not respect this ... If it does it is also a bug. ...
    (comp.lang.pascal.misc)
  • Re: CT,MA,NH specific
    ... >BTW, I'm not arguing -- there's nothing to argue about. ... but rather to skid in sideways, totally worn out, shouting "...holy shit...what a ride!" ...
    (rec.outdoors.rv-travel)
  • Re: Taken to court to recover a gift
    ... Btw, don't argue the details of the matter with her in the meantime; ... questions of the parties in a small claims action. ...
    (uk.legal)