Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: Obtuse smtpd

Re: Obtuse smtpd

From: Crispin Cowan <crispin_at_cse.ogi.edu>
Date: Thu, 09 Jul 1998 11:53:38 -0700

Joseph S. D. Yao wrote:

> Apparently, they only protect the return address in the most recent
> stack frame.

That was for protecting with the Pentium debug registers. We also did an
experiment where protection of the return address was done with a special
page-fault handler that we hacked into the kernel:

   * make the page non-writable
   * record the word you want to write
   * trap writes to the return address word and stop them
   * trap all other writes to the page and let them write through

In both cases (debug registers, and the page-fault handler) we found that
the overhead costs were ludicrously high, so we stopped development on
that line of work. The canary overheads are quite small, so development
continues.

Crispin
-----
 Crispin Cowan, Research Assistant Professor of Computer Science, OGI
    StackGuard: protect your software against Stack Smashing Attack
       http://www.cse.ogi.edu/DISC/projects/immunix/StackGuard/

                 Support Justice: Boycott Windows 98
Received on Jul 12 1998

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]