|
|||||||||||
|
Gera's Insecure Programing abo7
From: sin <sin(at)insolence.net>
Date: Thu May 29 2003 - 11:26:52 EDT
Hi. I'm working on Gera's insecure programing stuff, currently on abo7; as i
understand it, this is unexploitable on most (all?) current platforms
because of the order the sections are linked in?
the direct problem here being that .eh_frame and .dynamic directly follow
.data, so that i cant ever get control, because I can't overwrite useful
(to me) data without overwriting useful (to it) data.
So the thought that crosses my mind is why not just copy what is in
.eh_frame and .dynamic and .ctors until i reach .dtors; looking through
memory i see .dynamic is mostly 0 filled memory, which kinda; well it
screws that idea.
thanks
"Once set in motion, the process of questioning could come to but one end, the erosion of conviction and certitude and collapse into despair" (The Specter of the Absurd, 1988). -----BEGIN PGP SIGNATURE-----
iD8DBQE+1ia+oEcehqzkkpgRAkTRAJ4neEKtwBERz3sGhJ5rsgNvrJWusQCgq+2X
pmxZSAU8vxng1zY9vz6SHCU=
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:39 EDT |
||||||||||
|
|||||||||||