ibneko: (Default)
[personal profile] ibneko
http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1265116,00.html?track=NL-102&ad=594850&asrc=EM_NLN_1844405&uid=608727

...
"The common thought is that this kind of problem isn't exploitable. But we looked at this and thought, wouldn't it be neat if we could implement our own code on this server?" said Danny Allan, research director at Watchfire, based in Waltham, Mass. "The problem before was, you had to override the exact location that the pointer was pointing to. It was considered impossible. But we discovered a way to do this with generic dangling pointers and run our own shell code."
...


So it'll work for languages that don't do any garbage collection automagically. So C/++... not Java, probably not Perl or PHP... Mmm...

Expand Cut Tags

No cut tags

Profile

ibneko: (Default)
ibneko

Most Popular Tags

Style Credit

Page generated Feb. 13th, 2026 08:13 am
Powered by Dreamwidth Studios
January 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 2021