Research and Development

A follow up presentation to show more in-depth format string exploitation techniques.

What?

This presentation covers a method for exploiting format string vulnerabilities which is compared to techniques used for exploiting heap smashes. It does not not cover the basics of the vulnerability because these seem ten a panny.

Why?

Much work has been written about covering the underlying principles of format strings but not much seemed to be written concerning this specific technique. More over is was written to push forward a method and library that can be used to optimise format strings to fit into smaller buffer spaces.

Formatstringrevisited
formatstringrevisited.pdf
April 26, 2013
541.6 KiB
MD5 hash: e3fd1fbc64fe67b056a9001987bfc5ea
Details

Request to be added to the Portcullis Labs newsletter

We will email you whenever a new tool, or post is added to the site.

Your Name (required)

Your Email (required)