|
|||||||||||
|
Re: safe strcpy()?
From: Crispin Cowan <crispin(at)wirex.com>
Date: Tue Jan 28 2003 - 02:57:37 EST Ed Carp wrote: >start looking for a way to figure out how to determine how
There are two compiler enhancements for GCC that provide full bounds
checking on arrays (Bounded Pointers
More generally, you can read my survey of buffer overflow attacks and defenses here: "Buffer Overflows: Attacks and Defenses for the Vulnerability of the Decade". Crispin Cowan, Perry Wagle, Calton Pu, Steve Beattie, and Jonathan Walpole. DARPA Information Survivability Conference and Expo (DISCEX) <http://schafercorp-ballston.com/discex/>, Hilton Head Island SC, January 2000. Also presented as an invited talk at SANS 2000 <http://www.sans.org/sans2000/sans2000.htm>, Orlando FL, March 2000. PDF <http://wirex.com/%7Ecrispin/discex00.pdf>. It's now a little dated, in that PAX <http://pageexec.virtualave.net/>, libsafe <http://www.research.avayalabs.com/project/libsafe/>, and StackGhost <http://stackghost.cerias.purdue.edu/> came out since I wrote that paper. A more recent and comprehensive survey of open source security will appear shortly in the new IEEE Security&Privacy Magazine <http://www.computer.org/security/>. Oh yeah, and there's StackGuard <http://immunix.org/stackguard.html> :-) Crispin -- Crispin Cowan, Ph.D. Chief Scientist, WireX http://wirex.com/~crispin/ Security Hardened Linux Distribution: http://immunix.org Available for purchase: http://wirex.com/Products/Immunix/purchase.html Just say ".Nyet"
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:45 EDT |
||||||||||
|
|||||||||||