|
|||||||||||
|
Re: Anyone looked at the canary stack protection in Win2k3?
From: Ivan Arce <ivan.arce(at)corest.com>
Date: Wed Aug 06 2003 - 14:12:25 EDT You might want to take a look at Gerardo Richarte's paper: "Bypassing Stackshield and StackGuard protection" http://www.coresecurity.com/common/showdoc.php?idx=242&idxseccion=11
Abstract:
Techniques that exploit stack based buffer overflows on protected programs and environment have been presented in the past. Here we'll describe how the studied protections work, and then we'll present four more tricks to bypass stack smashing protections, some of which are extentions of older techniques, and some we think are novel. Mark Feldman wrote: > In-Reply-To: < 000101c34eaa$ecf34a80$0101a8c0@gfserver> > > Hi thomas > There is no need for a tool like IDA pro when you've got source code > available under your Visual C++ 7.0 CRT\SRC directory. > The security check is enabled by adding the /GS option to the compiler's > command line. > > These two links will explain microsoft's stack smashing protection: > > http://std.dkuug.dk/JTC1/SC22/WG21/docs/papers/2003/n1462.pdf > > http://msdn.microsoft.com/library/default.asp?url=/library/en- > us/dv_vstechart/html/vctchCompilerSecurityChecksInDepth.asp > > > Regards, > Mark Feldman >>From: "Andrew Thomas" <andrew@generator.co.za> Received on Wed Aug 6 14:22:52 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:40 EDT |
||||||||||
|
|||||||||||