OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Dailydave] Dangling pointers exploitation

pageexecfreemail.hu
Date: Wed Jul 25 2007 - 14:29:43 CDT


On 25 Jul 2007 at 14:03, Thomas Ptacek wrote:

> I'm not sure "saved return address on the stack" is the real vector
> for uninitialized variables.

it is not, nor were you talking about unitialized variables per se,
but this entirely 'new' class of bugs of wild pointers, which according
to you means:

> you have a pointer who's value seems unpredictable but is
> in fact strongly influenced by the execution environment which is in
> turn often influenced by inputs and timing.

you tell me why an overwritten return address doesn't qualify ;).

_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave