CiteULike is a free online bibliography manager. Register and you can start organising your references online.

Beyond stack smashing: recent advances in exploiting buffer overruns Export

Security & Privacy Magazine, IEEE, Vol. 2, No. 4. (2004), pp. 20-27.

Citation Format

[Posts]

View FullText article


krisn11's tags for this article

buffer_overrun stack_smashing

X Reviews [Write a review of this article]

X Notes for this article

krisn11 has 1 private note and 0 public notes for this article. If you are krisn11 then you can log in to see the private note.

X Find related articles from these CiteULike users

X Find related articles with these CiteULike tags

X Posting History

X Abstract

Security vulnerabilities related to buffer overruns account for the largest share of CERT advisories, as well as high-profile worms - from the original Internet Worm in 1987 through Blaster's appearance in 2003. When malicious crackers discover a vulnerability, they devise exploits that take advantage of the vulnerability to attack a system. The article describes three powerful general-purpose families of exploits for buffer overruns: arc injection, pointer subterfuge, and heap smashing. These new techniques go beyond the traditional "stack smashing" attack and invalidate traditional assumptions about buffer overruns.


X BibTeX record

X RIS record


Privacy Statement | Terms & Conditions
CiteULike organises scholarly (or academic) papers or literature and provides bibliographic (which means it makes bibliographies) for universities and higher education establishments. It helps undergraduates and postgraduates. People studying for PhDs or in postdoctoral (postdoc) positions. The service is similar in scope to EndNote or RefWorks or any other reference manager like BibTeX, but it is a social bookmarking service for scientists and humanities researchers.