OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [ANNOUNCE] glibc heap protection patch

From: Marco Ivaldi (raptor0xdeadbeef.info)
Date: Thu Dec 04 2003 - 09:22:37 CST


> So, unfortunately I don't think that check alone is sufficient.

For in-depth information about dlmalloc's frontlink() macro exploitation,
check out the excellent paper by MaXX, at:

http://phrack.org/phrack/57/p57-0x08

You can also see an exploitation example of mine (heap/heap2-ex.c) in the
misc-exploits.tgz collection, available at:

http://www.0xdeadbeef.info/code/misc-exploits.tgz

Cheers,

:raptor
--
Marco Ivaldi
Antifork Research, Inc. http://0xdeadbeef.info/
3B05 C9C5 A2DE C3D7 4233 0394 EF85 2008 DBFD B707