2003-02-03

Smashing the Stack

I was having a discussion about buffer overflows with a co-worker the other day.  I was describing to him how I was in awe by the ability of those who are able to get the overflow bits to work out in a way able to call a different address of code. The friend of mine, who let's just say happens to have a past with software vulnerabilities, responded to me in the respect of, "Na...it's really no big deal". He recommended that I read an article written by a "friend" of his:

"Smashing The Stack For Fun And Profit"

Shell code is the stuff that's stuffed into memory and executed by a buffer overflow.  With a set of basic tools like a C compiler and debugger one is able to take command of a system without much effort.
So I came back to my friend and said, "Okay...B***y.  You're right...it's not a big deal =)"

0 Comments:

Post a Comment

<< Home