
Dailydave mailing list archives
Re: No sellout. was: RE: Lynn / Cisco shellcode
From: Holden Williamson <limeyhaqr () gmail com>
Date: Tue, 2 Aug 2005 18:14:15 -0300
I think the major issues that Mike brought to light that most experienced people walked away from the presentation with (me included) were that there are ways to fool IOS's check_heaps function which preemptively reboots the device if something is amiss (usually thwarting most exploit attempts) and that the
Didn't FX@Phenoelit already cover this a year ago or more? If I remember correctly he described the whole process as "basic exploitation with a few tricky things".
upcoming versions of IOS will make exploitation MUCH easier by creating aligned address space across multiple versions of IOS, which currently change with each /build/ of the software.
And if your exploits are primitive enough that they can't work around not knowing exactly hard-coded where in memory they're aiming at with their write4 then .... OH I get it. People are happy because suddenly those with quasi-zero technical exploitation ability can write exploits for Cisco hardware. Makes sense now. <3 -holden _______________________________________________ Dailydave mailing list Dailydave () lists immunitysec com https://lists.immunitysec.com/mailman/listinfo/dailydave
Current thread:
- No sellout. was: RE: Lynn / Cisco shellcode surreal (Jul 28)
- Re: No sellout. was: RE: Lynn / Cisco shellcode security curmudgeon (Jul 29)
- Re: No sellout. was: RE: Lynn / Cisco shellcode Holden Williamson (Jul 29)
- Re: No sellout. was: RE: Lynn / Cisco shellcode byte_jump (Jul 29)
- Re: No sellout. was: RE: Lynn / Cisco shellcode Holden Williamson (Aug 01)
- Re: No sellout. was: RE: Lynn / Cisco shellcode byte_jump (Aug 01)
- Re: No sellout. was: RE: Lynn / Cisco shellcode Holden Williamson (Aug 01)
- Re: No sellout. was: RE: Lynn / Cisco shellcode I)ruid (Aug 02)
- Re: No sellout. was: RE: Lynn / Cisco shellcode Holden Williamson (Aug 02)
- Re: No sellout. was: RE: Lynn / Cisco shellcode I)ruid (Aug 02)
- Re: No sellout. was: RE: Lynn / Cisco shellcode byte_jump (Jul 29)
- <Possible follow-ups>
- RE: No sellout. was: RE: Lynn / Cisco shellcode Dennis Cox (Jul 29)
- RE: No sellout. was: RE: Lynn / Cisco shellcode Paul Melson (Aug 01)
- Re: No sellout. was: RE: Lynn / Cisco shellcode Holden Williamson (Aug 01)
- Re: No sellout. was: RE: Lynn / Cisco shellcode TAREK (Aug 02)
- Re: No sellout. was: RE: Lynn / Cisco shellcode M. Shirk (Aug 02)
- RE: No sellout. was: RE: Lynn / Cisco shellcode Todd Towles (Aug 02)