Secure Coding mailing list archives

Re: (Shellcode Injection)


From: "Louis Solomon [SteelBytes]" <louis () steelbytes com>
Date: Mon, 15 Dec 2003 11:15:26 +0000

The malicous code often spawns a shell,

External to the defective program, that could be avoided by running
the program in a process with insufficient quota to spawn a subprocess
(on operating systems that support such).

one can't always limit to that degree, as sometimes the program being hacked
has legitimate reasons for that much privilidge.

Louis Solomon
www.steelbytes.com








Current thread: