OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: quick question

From: Adam Gilmore (vulnoptusnet.com.au)
Date: Mon Aug 11 2003 - 09:00:32 CDT


Return-into-libc is probably your best bet, similar to the way you'd
exploit something with non-exec stacks. Not many other options .. if you
can control heap data you might be able to return into that.

-----Original Message-----
From: Cryptic_Phreak . [mailto:pondermatehotmail.com]
Sent: Monday, 11 August 2003 2:03 AM
To: vuln-devsecurityfocus.com
Subject: quick question

I'm not sure if this has been asked before by anyone; but how do you
exploit
a stack overflow with a random stackbase?

I've read bit of return-into-libc, is that what must be used?

_________________________________________________________________
The new MSN 8: smart spam protection and 2 months FREE*
http://join.msn.com/?page=features/junkmail