Re: Studying buffer overflows [maybe OT]

From: Jason Barbour (jbarbo1@gl.umbc.edu)
Date: 04/09/02


From: "Jason Barbour" <jbarbo1@gl.umbc.edu>
To: <vuln-dev@securityfocus.com>
Date: Tue, 9 Apr 2002 13:18:38 -0400

Did a quick search, is this the right paper?

http://mixter.warrior2k.com/exploit.txt

> Hrmm. I think you need to check out that nice paper from Mixer. It shows
> some nice stuff like that. Writing buffer overflow exploits - a tutorial
> for beginners is the name of it and since I'm nice here's a link:
>
> http://members.tripod.com/mixtersecurity/papers.html
>
> Link is prolly old and outdated so if it's gone don't ask where you can
> find it. Search. And good luck with those buffer overflows. they are nice,
> but VERY hard to get the hang of, that is if you don't have a vast
> knowledge of Memory. So yea, TIP: LEARN ALL ABOUT MEMORY



Relevant Pages

  • Re: [Full-disclosure] [Dailydave] What RedHat doesnt want you to know about ExecShield (without
    ... buffer overflow attacks by performing executable memory checks. ... This is not the case with ExecShield without NX. ... code execution, in the other you do not. ...
    (Full-Disclosure)
  • Re: IP Level Encryption
    ... The memory used by process A can be claimed by another process B ... >> will enable an attacker to execute arbitrary code, in Java this is ... any buffer overflow is detected and there is no ... Although I am also fond of Delphi, I don't think that it is a full ...
    (sci.crypt)
  • Re: understanding buffer overflow
    ... >> i went through the process of how a buffer overflow would work in my ... > $_FILES) so it consumes memory, you probably want to limit memory ... > per script execution, limiting post will make sure you have some ... # Parse error: parse error, ...
    (comp.lang.php)
  • Re: Buffer Overflow Errors
    ... >>it allows the OS to automatically kill any process that begins writing ... >>outside its own memory. ... an intentional malicious buffer overflow *never* writes outside ... > the end of the array. ...
    (comp.lang.java.programmer)
  • Re: localtime() core dumping
    ... I almost can gurantee that you have some buffer overflow before you call ... buffer overflow (read memory corruption) in some place preceding the ... Your debugtrace shows that actual SIGSEGV was inside memory ...
    (comp.unix.programmer)