4 ms·
Hey whoa pal, I didn't say I was going to hand him a copy of L0phtCrack and tell him to get to it (note my use of the word 'innocuous'): First of all, I said t
by jobeirne 17y ago
Hey whoa pal, I didn't say I was going to hand him a copy of L0phtCrack and tell him to get to it (note my use of the word 'innocuous'):
First of all, I said that we would be talking about deprecated tricks, just silly things where the exploit environment would have to be set up such that one could use these tricks.
Secondly, more of the citizenry should be aware exactly of how the most common exploits work as to prevent future pieces of software from suffering the same poor design.
Thirdly, I chose security topics because I myself am interested in them; I wanted to choose a topic that I'd be interested in as well because that way I have the tenacity to actually develop lesson plans, lectures and homework throughout the year.
- swolchok 17y ago"First of all, I said that we would be talking about deprecated tricks, just silly things where the exploit environment would have to be set up such that one could use these tricks." Even the crusty old stack-based buffer overflow can still be exploitable if the people who wrote the code in question didn't use any mitigations. It's plugging my own work, but the Green Dam censorware vulnerabilities from June (http://www.cse.umich.edu/~jhalderm/pub/gd http://www.cse.umich.edu/~jhalderm/pub/gd) were stack-based overflows, and I got a remote shell in the lab through Firefox on Windows XP. Apparently, DEP was not properly activated in that build of Firefox. It's even worse with unpatched XP, which, IIRC, has no DEP at all.