Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 22 guests online
 
Advertisement

You are here: Home arrow Featuresarrow /rootarrow [Article]-Understanding Heap Overflow Exploits
EH-Net
May 25, 2013, 10:17:54 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Understanding Heap Overflow Exploits  (Read 8680 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4169


Editor-In-Chief


View Profile WWW
« on: March 18, 2009, 11:02:24 AM »

Enjoy the audio and slide deck by Jack Koziol as your primer on heap overflow exploitation. Remember, if you want to learn this and much more directly from Jack, he will be teaching the CEPT course at ChicagoCon 2009s from May 4 - 8.

Permanent link: [Article]-Understanding Heap Overflow Exploits

Quote




Jack Koziol of Shellcoder's Handbook fame spoke at ChicagoCon last year on heap overflow exploitation, so we thought we'd share the entire audio recording and slide deck with you as an example of the type of talks you'll see at the next ChicagoCon in May 2009

As defined by Wikipedia, "A heap overflow is a type of buffer overflow that occurs in the heap data area. Like all buffer overflows, a heap overflow may be introduced accidentally by an application programmer, or it may result from a deliberate exploit. In either case, the overflow occurs when an application copies more data into a buffer than the buffer was designed to contain. A routine is vulnerable to exploitation if it copies data to a buffer without first verifying that the source will fit into the destination. A deliberate exploit may result in data at a specific location being altered in an arbitrary way, or in arbitrary code being executed."

So what does all that mean and how do you do it? Find out in Jack's talk on "the most common type of heap overflow exploits for Linux and Windows. He will briefly explain how dynamically allocated memory works, its interaction with the heap memory structure, and how a normal heap operates. Jack will then demonstrate how heap overflows occur, and how they can be exploited on Linux, Windows 2000 and Windows XP SP2 with Data Execution Prevention (DEP) enabled. Unfortunately, the Vista portion of the talk had to be withdrawn. Expect to laugh, cry, and be entertained!"


Let us know what you think.

Don
« Last Edit: March 18, 2009, 11:07:46 AM by don » Logged

CISSP, MCSE, CSTA, Security+ SME
NickFnord
Full Member
***
Offline Offline

Posts: 117



View Profile WWW
« Reply #1 on: March 18, 2009, 11:19:59 AM »

definately looking forward to this - I'm slowly creeping my way through shelcoders and havn't made the time to fully understand heap overflows yet - this should be good  :-)
Logged
vijay2
Full Member
***
Offline Offline

Posts: 220


View Profile
« Reply #2 on: March 18, 2009, 11:44:31 AM »

Nice,  Thanks Don
Logged

GPEN GCFA GCIH CISSP CISA GSEC OSCP C|EH Security+
jason
Hero Member
*****
Offline Offline

Posts: 1012



View Profile WWW
« Reply #3 on: March 19, 2009, 08:07:45 PM »

Very nice. Thanks much Don.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.062 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.