Re: Beating memory address randomization (secuirty) features in Unix/Linux
Andrea Purificato - bunker <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities |
|---|---|
| Message-ID | <[email protected]> |
Alle 15:52, sabato 25 marzo 2006, [email protected] ha scritto: > I've studied how to beat memory adress randomization. Does anyone know how > to beat memory address randomization in Unix/Linux? Today i've studied the problem on my linux box (2.6.15.6), and i've written two case study samples on the false line of "xgc" message: [jmp *%esp technic] http://rawlab.altervista.org/codes/exp/randstack/exp_jmp_rand.pl [call *%edx technic] http://rawlab.altervista.org/codes/exp/randstack/exp_call_rand.pl This second case study was developed trying to exploit famous "abo3.c" vulnerable program (see gera advanced overflow contest). I hope you like that! -- Andrea "bunker" Purificato +++++++++++[>++++++>+++++++++++++++++++++++++++++++++>++++ ++++++<<<-]>.>++++++++++.>.<----------.>---------.<+++++++. http://rawlab.altervista.org