Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Is DEP easily evadable?

Re: Is DEP easily evadable?

From: Ben Pfaff <blp_at_cs.stanford.edu>
Date: Thu, 13 Jan 2005 11:38:09 -0800

John Richard Moser <nigelenki_at_comcast.net> writes:

> PaX does pretty nice randomization. I think 15/16 for heap and stack
> and 24 for mmap(), though I could be overshooting the 24. I'm on amd64
> so I can't just run paxtest and see; though I could read the source code.

In some fairly reasonable circumstances, this may not be enough.
I wonder whether the security community is generally aware of a
paper I co-authored on defeating PaX and address space
randomization in general on 32-bit systems, titled "On the
Effectiveness of Address Space Randomization". It was presented
at CCS 2004 and available on my webpage, among other places:
        http://www.stanford.edu/~blp/papers/asrandom.pdf

-- 
"To prepare for the writing of Software,
 the writer must first become one with it,
 sometimes two."
--W. C. Carlson
Received on Jan 13 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]