Re: insecure signal handler design

From: Magosányi (magat_private)
Date: Tue May 29 2001 - 12:28:42 PDT

  • Next message: Ben Efros: "Re: TWIG SQL query bugs"

    A levelezőm azt hiszi, hogy Michal Zalewski a következőeket írta:
    > 
    > We are proud to announce our new security paper, "Delivering signals for
    > fun and profit". This paper is an attempt to discuss security aspects of
    []
    > For your convenience, it is attached to this message as well (20 kB). Your
    > feedback would be greatly appreciated.
    
    Hi!
    
    Is there any known exploit against real programs using this technique?
    The technique seems to work in a very low probability level due to
    the timing issues. But the first thing I have learned reading bugtraq
    is that if something is even remotely and theoretically exploitable,
    someone is using the technique for years already (and openbsd have
    fixed it two years ago:).
    



    This archive was generated by hypermail 2b30 : Wed May 30 2001 - 11:08:15 PDT