Re: problem in bypassing stack randomization ("call *%edx" technique)

Sebastian Krahmer <[email protected]> Mon, 8 Jan 2007 09:19:19 +0100 (CET)
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
On Fri, 5 Jan 2007, Loptr Chaote wrote:

> Modifying edx is theoretically possible via push/pop instructions..
> But finding the needed opcode combination in linux-gate.so.1 is
> (unfortunately) not possible.
This will be at randomized addresses soon anyways :)

Sebastian

-- 
~
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ [email protected] - SuSE Security Team
~