4 ms·
I have read about LoD/MoD, 8lGm etc..it seemed that low hanging fruit was probably the reasoning right? I mean, there were probably so many systems you could a
by makerops 13y ago
I have read about LoD/MoD, 8lGm etc..it seemed that low hanging fruit was probably the reasoning right? I mean, there were probably so many systems you could access through stupid bugs, that delving deep into SO wasn't necessary?
- tptacek 13y agoMaybe. But there was low-hanging fruit well into the late '90s (and remember that SQL Injection, the "ultimate" low-hanging fruit, is also a late '90s bug) --- but after the 8lgm stack overflow mania, there was a decisive shift towards using memory corruption to take over machines directly, rather than (say) overwriting strategic files on target systems with NFS bugs.
- makerops 13y agoVery True. Smashing the stack for fun and profit? That was the first interaction I had with more advanced techniques anyways. I read it as a soph/freshman in HS (97 or so I think)? Timing seems to be close. That could account for the explosion at least; I don't have any theories on the "dead" period.
- tptacek 13y agoI'm happy to give Elias credit for a big part of the shift, but the reality is that first x86 exploit was published well before that Phrack article, and people quickly repurposed it. (I'm a little biased here, since the author of that exploit is a partner of mine). The vulnerability research community in 1995 was very close-knit (not tiny, but you could fit them in a hotel banquet hall for Summercon), and they worked pretty quickly to educate each other about the attack.
- hect0r 13y agoInteresting. Who published it prior to Aleph One?