OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
'Return to libc' exploit

From: Dave Feustel (dfeustelmindspring.com)
Date: Sat Aug 14 2004 - 21:22:32 CDT


I am pretty sure that my user account on my 3.4 system
has been hacked, most likely as a result of a KDE or X11
vulnerability. _The Shellcoder's Handbook_ mentions
a 'return to libc' method of overcoming non-executeable
stacks implemented in Openbsd, etc. Is there a defense
needed against use of 'return to libc'?

Thanks,
Dave Feustel 260-422-5330