Skip to content

Comment on Smashing the stack for fun and profitparent

Comments

If you get lucky, your target won't bother with all these new-fangled protections and run on WinXP (no ASLR) and the only thing you'll have to contend with is non-executable stack. Our original exploit for Green Dam used a heap spray only to make writing it easier, and the underground exploit uses a really awful behavior of IE w.r.t. running .NET DLLs -- http://www.milw0rm.com/exploits/8938 . Other than that, there are no defenses to speak of.

Even that really awful behavior of IE, that's a Black Hat '09 talk, isn't it?

Black Hat talks are not necessarily "new". Black Hat is not an academic security conference. The exploit was released months before BH09.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.