insecure signal handler design

From: Michal Zalewski (lcamtufat_private)
Date: Mon May 28 2001 - 15:10:16 PDT

  • Next message: Michal Zalewski: "Unsafe Signal Handling in Sendmail"

    We are proud to announce our new security paper, "Delivering signals for
    fun and profit". This paper is an attempt to discuss security aspects of
    very common signal handler coding practices, describing theoretical
    background and demonstrating actual attack scenarios against live code in
    Unix environment.
    
    The paper is available at:
    
      http://razor.bindview.com/publish/papers/signals.txt
    
    For your convenience, it is attached to this message as well (20 kB). Your
    feedback would be greatly appreciated.
    
    -- 
    _____________________________________________________
    Michal Zalewski [lcamtufat_private] [security]
    [http://lcamtuf.coredump.cx] <=-=> bash$ :(){ :|:&};:
    =-=> Did you know that clones never use mirrors? <=-=
    
    
    



    This archive was generated by hypermail 2b30 : Mon May 28 2001 - 23:56:24 PDT