|
|||||||||||
|
Re: partial analysis of vulndev-1.c
From: <andrewg(at)d2.net.au>
Date: Tue May 13 2003 - 23:41:37 EDT > -----BEGIN PGP SIGNED MESSAGE-----
Without looking and finding the original mail, it sounds like an off by one malloc overflow. So to exploit that, iirc, its padding[fake fwd][fake bck]padding[amount to reach the fake chunk backwards. So it would be something like \xf8 or whatever you decide to use.
Hope this helps,
> -----BEGIN PGP SIGNATURE-----
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:39 EDT |
||||||||||
|
|||||||||||