2009-09-01ãã1ã¶æéã®è¨äºä¸è¦§
Boehm GCã¨çµã¿åãããå ´åã®æ³¨æç¹ã«ã¤ãã¦è¿°ã¹ãã æªãä¾ã ä¸ã®ãããªè¨è¿°ã§ã¯GC_malloc()ã§åå¾ãããã¤ã³ã¿ãé¨åé©ç¨ãããã®ã®ãèå¿ã®ã¡ã¢ãªé åãååããã¦ãã¾ãã使 ãã¨è¨ãã°ãGC_malloc()ã§åå¾ãããã¤ã³ã¿ããã¤ã³ã¿ãµã¤ãºå¢çã«ä½ç½®ãâ¦
http://d.hatena.ne.jp/yaneurao/20090927#p1ã®è©±ã ã¤ã¨ã¹ãã³ã»ãã¹ãã¨ããè¨èã®èª¬æããã ã¤ã¨ã¹ãã³ã»ãã¹ãã¨ã¯ 対象ã®ç¶æ ã«é¢ããã常ã«positive/negativeã®ä¸æ¹ãè¿ããã¹ã ã®ãã¨ãæãç§ã®é èªã 表ç¾ã®æãããçºçãããã¨ãããããé ç®æ°â¦
ãã£ã¨ãç°¡åãªææ®µããã£ã¨ãåªããææ®µã¨ãããã¨ããã°ãã°ããã calleeãã¹ã¿ãã¯ãè§£æ¾ããå ´å x86=IA32ã§ã®stdcall颿°ã®å ´åãcalleeãã¹ã¿ãã¯ãè§£æ¾ãããã¤ã¾ã call cãå¼ãã ç´å¾ã®ã¹ã¿ã㯠â¦â¦ 100 ret(c) jmp addãå¼ãã ç´å¾ã®ã¹ã¿ã㯠â¦â¦ 1â¦
ã¨æã£ããæ¢ã«ãã£ããhttp://d.hatena.ne.jp/shinichiro_h/20060119 å³å¯ã«ã¯ã #include <stdio.h> int test(int i, int j) { return i+j; } static int _i; int test1(int j) { return _i+j; } int (*test2(int i))(int) { _i = i; return test1; }å³å¯ã«ã¯ãint </stdio.h>â¦
http://d.hatena.ne.jp/shinichiro_h/20060119ã®ææ³ã¯å¼æ°ãç©ã¿ãªããã¦é¢æ°ãã¤ã³ã¿ãå¼ã¶ã¨ãããã®(ã ã¨æã)ã call cãå¼ãã ç´å¾ã®ã¹ã¿ã㯠â¦â¦ 100 ret(c) call addãå¼ãã ç´å¾ã®ã¹ã¿ã㯠â¦â¦ 100 ret(c) 100 10 ret(add) ã¨ããæãã§ããããtail â¦
http://d.hatena.ne.jp/kilrey/20090921#p1ã§ä½æããç¶ç¶ã¯æ¬å½ã«ãã¹ã¿ãã¯ãå·»ãæ»ãããã¨ããã§ããªããä¾ãã°ãå¤é¨ãªã½ã¼ã¹ãåå©ç¨ã§ããªããã¨ãã£ãåé¡ãããã å¤é¨ãªã½ã¼ã¹ãåå©ç¨ã§ããªãã ä¸ã®ã½ã¼ã¹ã³ã¼ãã§f1()ã§è¨é²ããç¶ç¶ãf2()ã§å·»â¦
Cè¨èªã§ç¶ç¶ãå®è£ ã§ããããèãã¦ã¿ãããã¡ãããçã®Cè¨èªã§ã§ããããããªãã®ã ãã©ãç°å¢ãå¶éããã°ã§ããªããã¨ããªãã åæãsetjmp()ã¨longjmp()ã«ã¤ãã¦ã setjmp()ã¨longjmp()ã®ç¨éã¯ããã¾ã§ã大åè±åºã§ããããã®ãããsetjmp()ãå¼ã³åºâ¦
ã¡ãã£ã¨å¤ããã©http://d.hatena.ne.jp/yuyarin/20090825/1251136545ã®è©±ã Cæ¨æºã§ã¯ã Cè¨èªã®ä»æ§ã¬ãã«ã§ã¯å¤å¤è¿å´ã«ãã£ã¨ãè¿ãã®ã¯æ§é ä½ã®å¤è¿å´ã ãè¤æ°ã®å¤ãè¿ãã¨ããç¨éã¯å åã«æºããã¦ããã struct int_int_t { int x; int y; }; struct â¦
http://www.kt.rim.or.jp/%7ekbk/zakkicho/09/zakkicho0909b.html#D20090916-2ã®è©±ã exploitable ãªæ å ±ã®æ ¼ç´ã广çã§ãªã (ineffective) æå·å (ã³ã³ãã¤ã«ãããã¹ã¯ã¼ããããã°ã©ã ã«åãè¾¼ãã symmetric ciphersãtrivial ãªãã¹ã¯ã¼ãããã¹ã¦ã®â¦
å¤æè®æSVNãåå§åããã¨ã®åãæºã¾ãå ´ã§è¦ã¦ãã¦æã£ãããã½ã¼ã¹ã³ã¼ãé²è¦§æã1.7.1,2ã«è¿½éããã¹ãã ãããã1.7.0ãå®å®çã¨ããããã§ããªãããã ãã追ãããã¦æ¯éã¯ãªãã¨æãã SVNã¨é£åããã¦updateâçæâuploadã¨ã§ããã¨è¯ãããã
ãåãã°è¯ããã¨è¨ã人ã¯ã¨ã©ã¼ãèµ·ãã¦ãããåããªããããªãããã¨æå¥ãè¨ãã仮令ããã®äººã®æä½ãééã£ã¦ããã¨ãã¦ãè¨ãããããåãã°è¯ããã¨è¨ã人ãé ·ããã°ã§å³å¾å·¦å¾ãã¦ããã®ãè¦ã¦(å°ãªãã¨ããã®äººã®)åå ã«æãå½ãã£ãã ãã®äººã¯ã³ã¼â¦
ã³ã¼ãã³ã¡ã³ãã«æ¸ãã¹ãã¯ãæå³ã - ããã°ã©ãã¼ã®è³ã¿ããã½ã¼ã¹ã³ã¼ãã®å¿è³åé¡ - ããã°ã©ãã¼ã®è³ã¿ãã®è©±ã åå¿è ã®ã³ã¼ãã§ããæå³ãæ¸ããã¦ãããªãã¬ãã¥ã¼ã¯å®¹æã«è¡ãããæå³ä¸æã®ã³ã¼ãã»ã©æã«è² ããªããã®ã¯ãªãã ãã³ã¡ã³ãã¨ãã¦â¦
http://itpro.nikkeibp.co.jp/article/COLUMN/20090208/324377/?ST=security&P=1ããhttp://d.hatena.ne.jp/tohokuaiki/20090910/encodingã®è©±ã ãã¼ã¹ã©ã¤ã³ã Webã¢ããªã±ã¼ã·ã§ã³ãããã§ã¯ä¸è¬çãªç¨æ³ã¨ãã¦æ¬¡ã®æ¡ä»¶ãæºãããã®ãã®è©±ã«éå®ãã¦é²ãâ¦
åã¨å®ã®é¢ä¿ã¯æ¥µãã¦åä»ãªãã®ã ãå ¨ãé¢ä¿ããªãã¨ãããã¨ã¯ãªããã®ã®ãã©ã¡ããã©ã¡ãã«å½±é¿ãä¸ãã¦ããããå¤ãã«ããããæ£ã®ç¸é¢ã§ããã¨ãéããªãã 宿ãããä½ãã«å¯¾ãã¦å¾ããååãä»ããã ãã®å ´åã¯ãåã¯ä½ã表ãããã¨ãå¤ããã¨ããâ¦
Cè¨èªã®å¦çéç¨ãèããã¨å¤§ã¾ãã«æ¬¡ã®ããã«ãªã£ã¦ããã 人éã®é ç·¨é ã½ã¼ã¹ã³ã¼ã ãã¼ã¹ æ½è±¡æ§ææ¨ ã³ã³ãã¤ã« ã¢ã»ã³ããªã³ã¼ã ã¢ã»ã³ãã« ãªãã¸ã§ã¯ãã³ã¼ã ãªã³ã¯ å®è¡ãã¡ã¤ã« OSã«ããèµ·å ããã»ã¹ ããã»ã¹å®è¡ åºå ããã¯å¿ ããã䏿ã«â¦
http://shinh.skr.jp/m/?date=20090831ã®è©±ãå忍è«ã¯é¢ç½ã話ãªã ãã«ã²ã£ãããã¨ãããå¤ãã è³æã§ããªããã¨ãããå°ãã²ã£ãããã®ã¯å忍è«ã®è©±ãæåè¦ãæã¯ããããªã¼é¢ç½ããªã¼ã¨æã£ãè¨æ¶ãããã ã§ããã¤ã ã£ãããã®è©±ãã¼ãããæãåºâ¦