Re: [ANNOUNCE] glibc heap protection patch

From: Stefan Esser (se_at_nopiracy.de)
Date: 12/04/03

  • Next message: OpenPKG: "[OpenPKG-SA-2003.051] OpenPKG Security Advisory (rsync)"
    Date: Thu, 04 Dec 2003 12:10:05 +0100
    To: xenophi1e <oliver.lavery@sympatico.ca>
    
    

    xenophi1e wrote:

    > This question seems more complex than 'Feel free to demonstrate me an
    > unlink exploit that works while my unlink macro is in place'. But I
    > have to admit my own ignorance here, I can't say for certain whether
    > an attacker who passes the test in your macro is left in a situation
    > where an exploit is possible.

    Fact is my macro makes arbitrary pointer overwrites with unlink()
    impossible. The magic value approach just makes it harder. You need to
    guess a 32bit value. Even if this is totally random it is theoreticly
    possible to exploit the unlink() macro in that case. And do not forget
    the power of information leak exploits.

    Just an example: The gamecube was hacked by an information leak exploit.
    A crc feature the Phantasy Star Online game allows to request checksums
    of arbitrary memory positions (and sizes).
    So it was possible for the smart guy who did it, to create a complete
    memory dump from
    remote. In that case your magic values are worthless...

    Stefan Esser


  • Next message: OpenPKG: "[OpenPKG-SA-2003.051] OpenPKG Security Advisory (rsync)"

    Relevant Pages

    • Re: Why field shading persists
      ... method of unlinking in that check boxes do not appear to unlink. ... This short macro will do it: ... all documents based on the template will stay unshaded -- even if the ... it will show field shading ...
      (microsoft.public.word.vba.general)
    • Re: Why field shading persists
      ... It sounds like unlinking form fields is what I seek. ... don't unlink it, it will show field shading just like the form fields would. ... It would be easy to modify the macro in various ways: ...
      (microsoft.public.word.vba.general)
    • Re: Why field shading persists
      ... The macro, as is, would unlink all the fields in the document, including the ... it will show field shading just like the form fields would. ... When you add macro code to a template in Word 2007, ...
      (microsoft.public.word.vba.general)
    • Re: Why field shading persists
      ... The following modification of the macro will unlink only form fields: ... there won't be any field shading because there ...
      (microsoft.public.word.vba.general)

  • Quantcast