Let's start out with some convenient types that allow bit twiddeling once we've subverted the type system....
well, not exactly but interesting anyway.
Monday, September 15, 2008
writing a .NET Security Exploit PoC...mmm?
Posted by
them
at
5:03 PM
0
comments
Wednesday, May 14, 2008
Misplaced Trust: Kerberos 4 Session Keys (1997)
Again, a 10 years old paper in badcoded. Ignore the past, repeat mistakes.
Misplaced Trust: Kerberos 4 Session Keys (1997)
Progress, far from consisting in change, depends on retentiveness. When change is absolute there remains no being to improve and no direction is set for possible improvement: and when experience is not retained, as among savages, infancy is perpetual. Those who cannot remember the past are condemned to repeat it. In the first stage of life the mind is frivolous and easily distracted, it misses progress by failing in consecutiveness and persistence. This is the condition of children and barbarians, in which instinct has learned nothing from experience.
George Santayana, The Life of Reason, Volume 1, 1905
Posted by
them
at
10:45 PM
0
comments
Wednesday, April 16, 2008
PHRACK #65
April 2008
by The Circle of Lost Hackers
0x01 Introduction TCLH
0x02 Phrack Prophile of The UNIX Terrorist TCLH
0x03 Phrack World News TCLH
0x04 Stealth Hooking: another way to subvert the Windows kernel mxatone
ivanlefou
0x05 Clawing holes in NAT with UPnP felinemenace
0x06 The only laws on Internet are assembly and RFCs Julia
0x07 Hacking the System Management Mode BSDaemon, coideloko, d0nand0n
0x08 Mystifying the debugger for ultimate stealthness halfdead
0x09 Australian Restricted Defense Networks and FISSO The Finn
0x0a Phook - The PEB Hooker shearer & dreg
0x0b Hacking the $49 Wifi Finder openschemes
0x0c The art of exploitation: Samba WINS stack overflow max_packetz
0x0d The Underground Myth anonymous
0x0e Hacking your brain: Artificial Conciousness -C
0x0f International scenes various
Posted by
them
at
10:08 PM
0
comments
Monday, April 14, 2008
Aplication-Specific Attacks - Leveraging the ActionScript Virtual Machine
Memory corruption vulnerabilities are becoming increasingly difficult to exploit, largely due to the protection mechanisms being integrated into most modern operating systems. As general protection mechanisms evolve, attackers are engaging in more specific, low-level application-targeted attacks. In order to refine general countermeasures (or at least raise awareness of their shortcomings), it is important to first understand how memory corruption vulnerabilities are exploited in some unique scenarios.
[...]
Aplication-Specific Attacks - Leveraging the ActionScript Virtual Machine by Mark Dowd PDF
Posted by
them
at
3:10 PM
0
comments
Saturday, April 5, 2008
gcc silently discards some wraparound checks...buf+len < buf?
David LeBlanc's Web Log
Vulnerability Note VU#162289
Basically, what it says is that code which looks like this:
char *buf;
int len;
gcc will assume that buf+len >= buf.
As a result, code that performs length checks similar to the following:
len = 1<<30;
[...]
if(buf+len < buf) /* length check */
[...perform some manipulation on len...]
are compiled away by these versions of gcc
Posted by
them
at
9:58 PM
0
comments
Tuesday, January 1, 2008
User Supplied Format String Vulnerability - everything ever written
Steve Christey
Advances in format string exploitation
Gerardo Richarte, Ricardo Quesada
Howto remotely and automatically exploit a format bug
Frédéric Raynal
scut team-teso
v1.1
v1.2
Format String Attack on alpha system
Seunghyun Seo (truefinder)
Format String Technique
sloth@nopninjas.com
Analysis of Format String Bugs
Andreas Thuemmel
Detecting Format String Vulnerabilities with Type Qualifiers
David Wagner
Large-Scale Analysis of Format String Vulnerabilities in Debian Linux
David Wagner
What are format bugs ?
Christophe BLAESS Christophe GRENIER Frédéreric RAYNAL
French
More info on format bugs
Pascal Bouchareine
Español
Format String Attacks
Tim Newsham
TXT
Format Bugs: What are they, Where did they come from,...How to exploit them
Lamagra
Español
Paper sobre format bugs
venomous
Exploiting the Libc Locale Subsystem Format String Vulnerability on Solaris/SPARC
Solar Eclipse
100 Most Influential Books Ever Written
See: scut/teso-team Format String paper
Posted by
them
at
6:06 PM
0
comments
Labels: badcoded, User Supplied Format String
Friday, December 28, 2007
New Microsoft Security Vulnerability Research and Defense blog
New Microsoft technical blog about security vulnerabilities RSS We are excited to have this outlet to share more in-depth technical information about vulnerabilities serviced by MSRC security updates and ways you can protect your organization from security vulnerabilities. You can read much more about the goals of the blog and about the SWI teams contributing to the blog in our “About” link: http://blogs.technet.com/swi/about.aspx
Posted by
them
at
11:01 AM
0
comments
Thursday, December 20, 2007
Double Free Vulnerabilities on Windows
by Matt Conover 2007
To learn to exploit real heap memory corruption vulnerabilities on Windows one of the things you have to do is to read every Matt Conover's publication. The next are two posts in the Symantec Security Response Blog about double free() bugs. More articles and publications by him will be posted later in this blog.
In light of the recent CSRSS double free bug, I wanted to provide some information on the exploitation of double frees on Windows on XP SP2 and later. Prior to XP SP2, double frees were trivial to exploit, but now the security cookie (in each heap chunk) and safe unlinking checks make it more difficult to exploit. So this blog entry will discuss the exploitability on XP SP2 and later heap implements.
Double Free Vulnerabilities Part 1
Double Free Vulnerabilities Part 2
Posted by
them
at
2:23 PM
0
comments
Labels: badcoded, Matt Conover, Windows Heap
Tuesday, December 18, 2007
Smashing The Modern Stack For Fun And Profit
Craig J. Heffner article about the problems he found while reading and following the examples in Smashing The Stack For Fun And Profit using a modern Linux system.
"...the GNU C Compiler (gcc) has evolved since 1998, and as a result, many people are left wondering why they can't get the examples to work for them, or if they do get the code to work, why they had to make the changes that they did. Having these same problems myself, and being unable to find an updated version of Aleph One's document on the web, I set out to identify the source of these variations on my own. ..."
Smashing The Modern Stack For Fun And Profit
Posted by
them
at
6:06 PM
0
comments
Labels: badcoded
Sunday, December 16, 2007
Valgrind 3.3.0 released
Valgrind is an award-winning suite of tools for debugging and profiling Linux programs. With the tools that come with Valgrind, you can automatically detect many memory management and threading bugs, avoiding hours of frustrating bug-hunting, making your programs more stable. You can also perform detailed profiling, to speed up and reduce memory use of your programs.
The Valgrind distribution currently includes four tools: a memory error detector, a cache (time) profiler, a call-graph profiler, and a heap (space) profiler. It runs on the following platforms: X86/Linux, AMD64/Linux, PPC32/Linux, PPC64/Linux.
The main excitement in 3.3.0 is new and improved tools. Helgrind
works again, Massif has been completely overhauled and much improved,
Cachegrind now does branch-misprediction profiling, and a new category
of experimental tools has been created, containing two new tools:
Omega and DRD. There are many other smaller improvements. [...]
Posted by
them
at
5:14 PM
0
comments
Labels: Secure Coding, tools
Phrack Magazine #64
May 2007
by The Circle of Lost Hackers
0x01 Introduction The Circle of Lost Hackers
0x02 Phrack Prophile of the new editors The Circle of Lost Hackers
0x03 Phrack World News The Circle of Lost Hackers
0x04 A brief history of the Underground scene The Circle of Lost Hackers
0x05 Hijacking RDS TMC traffic information signal lcars
danbia
0x06 Attacking the Core: Kernel Exploitation Notes twiz
sgrakkyu
0x07 The revolution will be on YouTube gladio
0x08 Automated vulnerability auditing in machine code Tyler Durden
0x09 The use of set_head to defeat the wilderness g463
0x0a Cryptanalysis of DPA-128 sysk
0x0b Mac OS X Wars - A XNU Hope nemo
0x0c Hacking deeper in the system scythale
0x0d The art of exploitation: Autopsy of cvsxpl Ac1dB1tch3z
0x0e Know your enemy: Facing the cops Lance
0x0f Blind TCP/IP hijacking is still alive Lkm
0x10 Hacking your brain: The projection of consciousness keptune
0x11 International scenes Various
Posted by
them
at
4:03 PM
0
comments
Putting risk in perspective: Do people make better decisions when they understand average risk?
Putting risk in perspective: Do people make better decisions when they understand average risk? from PhysOrg.com
If there were a pill that would cut your risk of breast cancer in half, would you take it? What if you were told your risk of breast cancer was already below average?
[...]
Posted by
them
at
3:25 PM
0
comments
Labels: risk
Defend Your Code with Top Ten Security Tips Every Developer Must Know

MSDN Magazine, September 2002
Michael Howard and Keith Brown
Content
- 1. Trust User Input at Your Own Peril
- 2. Protect Against Buffer Overruns
- 3. Prevent Cross-site Scripting
- 4. Don't Require sa Permissions
- 5. Watch that Crypto Code!
- 6. Reduce Your Attack Profile
- 7. Employ the Principle of Least Privilege
- 8. Pay Attention to Failure Modes
- 9. Impersonation is Fragile
- 10. Write Apps that Non-admins Can Actually Use
Posted by
them
at
11:41 AM
0
comments
Labels: badcoded, Secure Coding
Friday, December 14, 2007
CERT Secure Coding Projects
http://www.cert.org/secure-coding/
CERT Secure Coding Standards
A collaborative site that provides rules and recommendations for secure coding practices in the C and C++ programming languages
Managed string library
The managed string library provides a more secure alternative to standard null-terminated byte strings in C. Managed string functions dynamically allocate memory as required, eliminating the possibility of buffer overflows, string truncation, and other common programming errors.
Secure integer library
This library includes functions for safe integer conversions and arithmetic operations.
Publications Podcast RSS
Posted by
them
at
9:36 PM
0
comments
Labels: badcoded, Secure Coding
Automatic Discovery of API-Level Exploits
Not very interesting besides the title and abstract. It could be included it in the "everything ever written about format strings vulnerabilities" section.
PDF
By Vinod Ganapathy, Sanjit A. Seshia, Somesh Jha, Thomas W. Reps, Randal E. Bryant
Abstract
We argue that finding vulnerabilities in software components is different from finding exploits against them. Exploits that compromise security often use several low-level details of the component, such as layouts of stack frames. Existing software analysis tools, while effective at identifying vulnerabilities, fail to model low-level details, and are hence unsuitable for exploit-finding. We study the issues involved in exploit-finding by considering application programming interface (API) level exploits. A software component is vulnerable to an API-level exploit if its security can be compromised by invoking a sequence of API operations allowed by the component. We present a framework to model low-level details of APIs, and develop an automatic technique based on bounded, infinite-state model checking to discover API-level exploits. We present two instantiations of this framework. We show that format-string exploits can be modeled as API-level exploits, and demonstrate our technique by finding exploits against vulnerabilities in widely-used software. We also use the framework to model a cryptographic-key management API (the IBM CCA) and demonstrate a tool that identifies a previously known exploit.
Posted by
them
at
7:10 PM
0
comments
Labels: badcoded, bounded mdoel checking