3 ms·
I think what he means with historically is before ASLR, DEP, and other mitigations, where a buffer overflow meant you can simply overwrite the return pointer at
by tmsbrg 5y ago
I think what he means with historically is before ASLR, DEP, and other mitigations, where a buffer overflow meant you can simply overwrite the return pointer at ESP, jump to the stack and run any shellcode. Mitigations have made exploitation much, much more complex nowadays. See for example https://github.com/stong/how-to-exploit-a-double-free https://github.com/stong/how-to-exploit-a-double-free
- onphonenow 5y agoExactly. This escape is technically quite cool frankly in terms of some creativity. That said, my own view is that messages from untrusted contacts should be straight ascii, parsed in a memory safe language with no further features until you interact (ie, write back etc).
- mcculley 5y agoSafeguards should be applied uniformly to all senders. A trusted sender could have been already exploited.
- onphonenow 5y agoIt's this attitude that is diminishing our security posture. Users want gifs, they want shared locations, they want heart emojies, they want unicode. The fact that you force EVERY user you interact with to have them same treatment is the problem. Some people, I left into my house unsupervised. Some as guests. Some I don't let in at all. We need to start modeling this approach online more. I don't think you understand how far users will go to work around safeguards if they interfere with their daily life.
- mcculley 5y ago> Users want gifs, they want shared locations, they want heart emojies, they want unicode. I want all of those things. I use them every day. I don't trust any of my contacts to not have an infection.