|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Future of buffer overflows ?
From: Crispin Cowan (crispin
WIREX.COM)Date: Thu Nov 02 2000 - 00:19:31 CST
- Next message: Neil W Rickert: "Re: vulnerability in mail.local"
- Previous message: Claes Nyberg: "Redhat 6.2 dump Exploit"
- In reply to: Michal Zalewski: "Re: Future of buffer overflows ?"
- Next in thread: tseeker
PROBEMAIL.COM: "Re: Future of buffer overflows ?"
- Reply: Crispin Cowan: "Re: Future of buffer overflows ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Michal Zalewski wrote:
> need to execute code passed on stack. Just it is the simpliest and most
> accurate way. All techniques - libsafe, StackGuard, PaX, etc - are still
> only a workarounds, not a solutions.
I take exception to this claim. StackGuard is not a workaround: for the
vulnerabilities that StackGuard stops, it really stops them. There is not a
way to craft a different attack against the same vulnerability such that it
will bypass StackGuard.
That is not to say that StackGuard is a complete solution: there are
vulnerabilities that StackGuard does not protect against. But to beat
StackGuard, you must go find a new vulnerability: tweeking the one
StackGuard is blocking will not help.
This is distinct from both the Openwall non-excutable stack segment, and the
PAX non-executable data pages approaches. With those defenses, attacks that
are stopped by Openwall and PAX can *always* be re-worked to bypass the
Openwall and PAX defenses, *without* having to go find a new vulnerability to
exploit.
Crispin
-- Crispin Cowan, Ph.D. Chief Research Scientist, WireX Communications, Inc. http://wirex.com Free Hardened Linux Distribution: http://immunix.org
- Next message: Neil W Rickert: "Re: vulnerability in mail.local"
- Previous message: Claes Nyberg: "Redhat 6.2 dump Exploit"
- In reply to: Michal Zalewski: "Re: Future of buffer overflows ?"
- Next in thread: tseeker
PROBEMAIL.COM: "Re: Future of buffer overflows ?"
- Reply: Crispin Cowan: "Re: Future of buffer overflows ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]