ROP Exploitation without Code Injection.pdf
(
4147 KB
)
Pobierz
Return-oriented Programming:
Exploitation without Code Injection
Erik Buchanan, Ryan Roemer, Stefan Savage, Hovav Shacham
University of California, San Diego
Bad code versus bad behavior
“Bad”
Bad
behavior
“Good”
Good
behavior
Attacker
d
code
Application
d
code
Problem: this implication is
false!
The Return-oriented programming thesis
Return oriented
any sufficiently large program codebase
arbitrary attacker computation and behavior,
without
code injection
(in the absence of control-flow integrity)
Security systems endangered:
W-xor-X aka DEP
Linux, OpenBSD,
Linux OpenBSD Windows XP SP2 MacOS X
SP2,
Hardware support: AMD NX bit, Intel XD bit
Trusted computing
p
g
Code signing: Xbox
Binary hashing: Tripwire, etc.
… and others
Return-into-libc and W^X
Plik z chomika:
WMatrixie
Inne pliki z tego folderu:
StegoSploit - Exploiting the Browser using only Images.pdf
(33848 KB)
Access Denied - Guide for Code Breakers.pdf
(5201 KB)
Exploiting Software - How To Break Code.pdf
(7765 KB)
Linux Kernel Crash Book - Everything you need to know.pdf
(4992 KB)
Runtime Attacks - Buffer Overflow and Return-Oriented-Programming.pdf
(6793 KB)
Inne foldery tego chomika:
Reversing
Tools
Zgłoś jeśli
naruszono regulamin