OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Dailydave] Dangling pointers exploitation

From: Matt (mattuse.net)
Date: Wed Jul 25 2007 - 13:06:32 CDT


On Wed, 25 Jul 2007, Thomas Ptacek wrote:

> Unitialized automatic variables and use-after-free variables seem
> of-a-kind: you have a pointer who's value seems unpredictable but is
> in fact strongly influenced by the execution environment which is in
> turn often influenced by inputs and timing.

Right. It's almost as if going through the Purify and Insure++
documentation from 10+ years ago is a veritable gold-mine for new types
of exploitable bugs.

--
tangled strands of DNA explain the way that I behave.
http://www.clock.org/~matt
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave