Smashing the Stack
I was having a discussion about buffer overflows with a co-worker the other day. I was describing to him how I was in awe by the ability of those who are able to get the overflow bits to work out in a way able to call a different address of code. The friend of mine, who let's just say happens to have a past with software vulnerabilities, responded to me in the respect of, "Na...it's really no big deal". He recommended that I read an article written by a "friend" of his:
"Smashing The Stack For Fun And Profit"
Shell code is the stuff that's stuffed into memory and executed by a buffer overflow. With a set of basic tools like a C compiler and debugger one is able to take command of a system without much effort.
So I came back to my friend and said, "Okay...B***y. You're right...it's not a big deal =)"

0 Comments:
Post a Comment
<< Home