Windows 2003 Server - Defeating the stack protection mechanism
From: NGSSoftware Insight Security Research (nisr_at_NEXTGENSS.COM)
Date: 09/11/03
- Previous message: Geoff Vass: "Re: Norton Internet Security 2003 blacklist fault?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 11 Sep 2003 15:40:20 +0100 To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
For those interested, NGSS has just published a paper describing how to
defeat the mechanism built into Windows 2003 Server to prevent exploitation
of stack based buffer overflow vulnerabilities. Previous work done in this
area presented methods that only worked in highly specific scenarios - the
new methods presented in this paper are generic. The paper can be downloaded
from http://www.nextgenss.com/papers/defeating-w2k3-stack-protection.pdf .
Cheers,
David Litchfield
NGSSoftware Ltd
http://www.nextgenss.com/
+44(0)208 401 0070
---- Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER! With a growth rate exceeding 110%, the TICSA security practitioner certification is one of the hottest IT credentials available. And now, for a limited time, you can save 33% off of the TICSA certification exam! To learn more about the TICSA certification, and to register as a TICSA candidate online, just go to http://www.trusecure.com/offer/s0100/ ----
- Previous message: Geoff Vass: "Re: Norton Internet Security 2003 blacklist fault?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|