| From: | Florian Weimer <Weimer(at)CERT(dot)Uni-Stuttgart(dot)DE> |
|---|---|
| To: | pgsql-hackers(at)postgresql(dot)org |
| Subject: | Re: @(#)Mordred Labs advisory 0x0003: Buffer overflow in |
| Date: | 2002-08-22 11:30:19 |
| Message-ID: | 87wuqjuo50.fsf@CERT.Uni-Stuttgart.DE |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
Gavin Sherry <swm(at)linuxworld(dot)com(dot)au> writes:
> It would be perhaps one of the most impressive hacks ever if someone
> could dream machine code to put in the overrun which consisted
> entirely of printable characters.
At least for the x86 architecture, working ASCII-only shell code
exists (even shell code which consists just of letters!). See for
example:
http://cert.uni-stuttgart.de/archive/vuln-dev/2000/10/msg00200.html
ASCII-only shellcode for RISC platforms is even harder and might be
impossible.
--
Florian Weimer Weimer(at)CERT(dot)Uni-Stuttgart(dot)DE
University of Stuttgart http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT fax +49-711-685-5898
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Tom Lane | 2002-08-22 13:43:05 | Re: Release of v7.2.2 (Was: Re: @(#)Mordred Labs ad...) |
| Previous Message | Teodor Sigaev | 2002-08-22 10:31:29 | Please, apply patch |