Tuesday, 16 March 2010

lately

I haven't posted in quite some time. However I have been fairly active in these last couple of weeks.
I've kept working at the wargames, and in addition to that, I was given a few private crackmes/exploitmes. Due to their nature I wasn't able to post the solutions.
I can however say that they were quite interesting. First and foremost I only had the binary, which differs somewhat from what I was used to as far as exploitme's go. One of them consisted of a a buffer-overflow enabled by an integer "underflow", which would in turn help bypass a stack canary, with a return into .TEXT (something I had never done before). The second one, was my very first introduction to heap-overflows, and it was awesome :).

Mainly motivated by corelan's post I am now trying to move from exploitme's to "real world" vulnerabilities.