RE: Exploiting Buffer Overflows on Compaq Tru64 and No-Exec Stack

From: Sam Pointer (sam.pointerat_private)
Date: Thu May 16 2002 - 08:57:41 PDT

  • Next message: dev-null@no-id.com: "Re: Exploiting Buffer Overflows on Compaq Tru64 and No-Exec Stack"

     
    -----BEGIN PGP SIGNED MESSAGE-----
    
    Try this artice: http://www.phrack.org/show.php?p=57&a=5 for 64-bit
    code, and this article http://www.phrack.org/show.php?p=58&a=4 for
    non-stack exploit techniques.
    
    Hope this helps.
    
    - -----Original Message-----
    From: helmut schmidt [mailto:helmutsch69at_private]
    Sent: 16 May 2002 09:29
    To: vuln-devat_private
    Subject: Exploiting Buffer Overflows on Compaq Tru64 and No-Exec
    Stack
    
    
    Hi,
    
    I have been testing buffer overflows on Compaq Tru64. However, all my
    examples execute code on the stack. Tru64 comes with a default 
    non-executable stack.
    
    How can one exploit a Tru64 buffer overflow without executing code on
    the 
    stack ? I would appreciate any techniques / White papers or coding
    examples 
    that I can use to further my understanding of these issues in a
    64-bit 
    environment.
    
    Thanks in advance for any help, Helm
    
    _________________________________________________________________
    Get your FREE download of MSN Explorer at
    http://explorer.msn.com/intl.asp.
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP 7.0.4
    
    iQCVAwUBPOPaFbZuYukPoxS2AQFJ/QP+ISLnaAoS39b0SfPUELfy2/w9UyxeP2TX
    czbBGTtGd27piFTnPHOU6yQ69Xv4fnfBjeBlNV7DZAOI6ni0YKqkooudHH8/AqGf
    rsJ8VAQqAGl/jUN5YKdz6kvQC3RLglAPW3iHRe5r0X13P++9ll1isUH+2lYLpGUx
    OV1EI0y4Xx0=
    =ECd4
    -----END PGP SIGNATURE-----
    
    
    This email and any attachments are strictly confidential and are intended
    solely for the addressee. If you are not the intended recipient you must
    not disclose, forward, copy or take any action in reliance on this message
    or its attachments. If you have received this email in error please notify
    the sender as soon as possible and delete it from your computer systems.
    Any views or opinions presented are solely those of the author and do not
    necessarily reflect those of HPD Software Limited or its affiliates.
    
     At present the integrity of email across the internet cannot be guaranteed
    and messages sent via this medium are potentially at risk.  All liability
    is excluded to the extent permitted by law for any claims arising as a re-
    sult of the use of this medium to transmit information by or to 
    HPD Software Limited or its affiliates.
    



    This archive was generated by hypermail 2b30 : Thu May 16 2002 - 12:36:37 PDT