Full Disclosure mailing list archives

Re: New security ezine released


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Fri, 28 May 2004 02:09:04 +1200

Christian Ney <chris () roothell org> wrote:

There's only one way to find out: compile this stuff and use "strings
BINARY|tail -2" on the binary, then your question should be answered
completely, even without having to try it out (which I wouldn't advise you
to do). ;)

There are easier/quicker ways than that...

If what you propose will be useful (which it will _IN THIS CASE_) then 
simply "hex to binary" decoding the hex-ified overflow data blocks will 
(normally) also work, as it did here and requires a much lighter 
toolset than a full-blown build environment.


Regards,

Nick FitzGerald

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: