Metasploit mailing list archives

mcafee Entercept


From: DAVID.G.WESTON at saic.com (Weston, David G.)
Date: Tue, 30 Oct 2007 08:22:01 -0700

Hi All,
  Has anyone had luck with various payloads and mcafee entercept?
Theres a paper out of the Naval War college
http://www.nps.navy.mil/Content/CS/ncrowe/oldstudents/labbe_thesis.htm
where the author test various exploits from metasploit/core vs mcafee
entercept and cisco security agent.  Does anyone have any experience in
this area?  There's a paper in Phrack 62 about evading third party
buffer overflow protection and I have had some success with the
technique of using a return address in the process space marked
read-only for the final stack frame but does anyone having tricks to add
to this?

Thanks,
Dave



Current thread: