Vulnerability Development mailing list archives

hardware protection for format string attacks


From: Mariusz Woloszyn <emsi () ipartners pl>
Date: Wed, 28 Nov 2001 22:09:42 +0100 (EET)


Does anyone successfuly exploited any format string vulnerability on
PA-RISC architecture (on any other archjitecture with aligned memory
access)??? 
I mean: does architecture here prevents from exploiting it?
Format string exploitation using %n requires (let's say) 4 unaligned
memory writes to overwrite address in memory. If i try to write to
unaligned address i'm getting SIGBUS.

Does anyone has any ideas?

--
Mariusz Wołoszyn
Internet Security Specialist, Internet Partners


Current thread: