« Custom car guage faces | Main | Wireless LAN performance improvement »

Format string attacks

Who knew an incorrect printf statement could actually allow someone to spawn a root shell (using %n). Several docs pointed out by Cyrus Durgin on format string attacks.
http://www.lava.net/~newsham/format-string-attacks.pdf
http://www.team-teso.net/releases/formatstring-1.2.tar.gz

The first is a little light on content, but very well written. The second is full of content however many of the code examples are poorly written (also note that many were written with Sparc Solaris specifics).

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)