Re: Java and buffer overflows
From: Dave Aitel (dave@immunitysec.com)Date: 06/26/02
- Previous message: John Madden: "Re: OpenSSH Vulns (new?) Priv seperation"
- In reply to: Nelson Sampaio Araujo Junior: "Re: Java and buffer overflows"
- Next in thread: KF: "Re: Java and buffer overflows"
- Next in thread: Rafael Anschau: "Re: Java and buffer overflows"
- Reply: KF: "Re: Java and buffer overflows"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Dave Aitel <dave@immunitysec.com> To: Nelson Sampaio Araujo Junior <nelson@lunenetworks.com.br> Date: 26 Jun 2002 13:08:18 -0400
Although, as another poster said, native code invocation is going to
continue to be a problem for managed languages such as Java and C# in
the years to come.
I've found a buffer overflow in native code invoked by a major
application server that happened to be written in Java. It's fixed now,
btw. :>
-dave
On Tue, 2002-06-25 at 20:40, Nelson Sampaio Araujo Junior wrote:
> Hi,
>
> > I heard thatt java is invulnerable to bofs
> > Has anyone succefully exploited a bof in java ?
>
> Please notice that buffer overflow is only one way of software exploitation.
> Generalizing the concept, any procedure that makes a software work badly,
> and if possible be directed to do something you want (and obviously not
> authorized), can be considered exploitation.
>
> Please does not sit down and relax just because Java should not have buffer
> overflows. There are inifinite ways of directing a software to do something
> bad or not expected, and once more, buffer overflows (or overruns if you
> prefer) is *just* one option.
>
> Regards,
>
> Nelson Junior
> nelson@lunenetworks.com.br
> nelson@LUNE.com.br
>
>
- application/pgp-signature attachment: This is a digitally signed message part
- Previous message: John Madden: "Re: OpenSSH Vulns (new?) Priv seperation"
- In reply to: Nelson Sampaio Araujo Junior: "Re: Java and buffer overflows"
- Next in thread: KF: "Re: Java and buffer overflows"
- Next in thread: Rafael Anschau: "Re: Java and buffer overflows"
- Reply: KF: "Re: Java and buffer overflows"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|