Bugtraq mailing list archives
Re: non-exec stack
From: neldredge () HMC EDU (Nate Eldredge)
Date: Wed, 10 May 2000 17:20:35 -0700
Gert Doering writes:
Hi, On Mon, May 08, 2000 at 10:06:04AM +0200, Casper Dik wrote:Here's an overflow exploit that works on a non-exec stack on x86 boxes. It demonstrates how it is possible to thread together several libc calls. I have not seen any other exploits for x86 that have done this..Non-executable stacks do not work in Solaris/x86. It is impossible to give page level protection that prevents execution on the x86 architecture.Hmmm, so how do they do that on Linux? I thought Solar Designer had a non-exec-stack patch for Linux.
Presumably you could map the code segment so as to exclude the stack. Then, since a user-mode program cannot change the segmentation without kernel assistance, the stack would then not be executable. -- Nate Eldredge neldredge () hmc edu
Current thread:
- non-exec stack Tim Newsham (May 06)
- "I don't think I really love you" Michal Zalewski (May 07)
- Re: non-exec stack Casper Dik (May 08)
- Re: non-exec stack Gert Doering (May 09)
- Re: non-exec stack Casper Dik (May 09)
- Re: non-exec stack Nate Eldredge (May 10)
- »Ø¸´: Re: non-exec stac ZhaoQian (May 10)
- Alert: IIS ism.dll exposes file contents Cerberus Security Team (May 11)
- ISSalert: Internet Security Systems Security Advisory: Microsoft IIS Remote Denial of Service Attack Warren Barrow (May 11)
- Remote DoS attack in Internet Information Server 4.0 & 5.0 "Malformed Extension Data in URL" Vulnerability Ussr Labs (May 11)
- Microsoft Security Bulletin (MS00-030) Microsoft Product Security (May 11)
- IE Domain Confusion Vulnerability Foo Bar (May 11)
- Overflow in Outlook Express 4.* - too long filenames with graphic format extension Ultor (May 12)
- Eudora Sensitive to Long Filenames Ron Moritz (May 18)
- IE Domain Confusion Vulnerability is an Email problem also Richard M. Smith (May 12)
- Re: IE Domain Confusion Vulnerability doesn't matter much Marc Slemko (May 12)
- Re: non-exec stack Gert Doering (May 09)