[Dailydave] Dangling pointers exploitation
Tyler Krpata
krpatasec at gmail.com
Wed Jul 25 18:11:03 EDT 2007
Keeping in mind that "uninitialized" and "previously valid" have some
important differences.
On 7/25/07, Thomas Ptacek <tqbf at matasano.com> wrote:
> I'm not sure "saved return address on the stack" is the real vector
> for uninitialized variables.
>
> On 7/25/07, pageexec at freemail.hu <pageexec at freemail.hu> wrote:
> > On 25 Jul 2007 at 12:02, Thomas Ptacek wrote:
> >
> > > you have a pointer who's value seems unpredictable but is
> > > in fact strongly influenced by the execution environment which is in
> > > turn often influenced by inputs and timing.
> >
> > such as... a saved return address on the stack? isn't that kinda old
> > news these days? ;-)
> >
> >
>
>
> --
> ---
> Thomas H. Ptacek // matasano security
> read us on the web: http://www.matasano.com/log
> _______________________________________________
> Dailydave mailing list
> Dailydave at lists.immunitysec.com
> http://lists.immunitysec.com/mailman/listinfo/dailydave
>
More information about the Dailydave
mailing list