Re: Beating memory address randomization (secuirty) features in Unix/Linux

Andrea Purificato - bunker <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
Alle 15:52, sabato 25 marzo 2006, [email protected] ha scritto:
> I've studied how to beat memory adress randomization.  Does anyone know how
> to beat memory address randomization in Unix/Linux? 

Today i've studied the problem on my linux box (2.6.15.6), and i've written 
two case study samples on the false line of "xgc" message:

[jmp *%esp technic]
http://rawlab.altervista.org/codes/exp/randstack/exp_jmp_rand.pl

[call *%edx technic]
http://rawlab.altervista.org/codes/exp/randstack/exp_call_rand.pl

This second case study was developed trying to exploit famous "abo3.c" 
vulnerable program (see gera advanced overflow contest).

I hope you like that!
-- 
Andrea "bunker" Purificato
+++++++++++[>++++++>+++++++++++++++++++++++++++++++++>++++
++++++<<<-]>.>++++++++++.>.<----------.>---------.<+++++++.

http://rawlab.altervista.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.