2014-06-01ãã1ã¶æéã®è¨äºä¸è¦§
ãImproper Null Terminationãå©ç¨ããSSPåé¿ãã§ã¯ãstack canaryã®å é ã«ããNULLãã¤ããä¸æ¸ããããã¨ã§canaryã®èªã¿åºããè¡ã£ãã ãã®æ¹æ³ã®ã»ãã«ãããããã¯ã¼ã¯ãµã¼ããforkãµã¼ãã¨ãã¦å®è£ ããã¦ããå ´åã1ãã¤ããã¨ã®ãã«ã¼ããã©ã¼ã¹ã§câ¦
http://jsfiddle.net/yemS9/ Google Chrome 33以éã¾ãã¯Safari 7.0ã§ã¢ã¯ã»ã¹ããã¨ãåºå ã¢ãã¦ã³ã¹ãæµããã var chineses = [ "亲ç±ç顾客æåï¼ä½ 们好ã", "è¡·å¿æ¬¢è¿æ¨å 临åé½å «åã", "åé½å «åæ¯æ¥æ¬èåç大åè´ç©ä¸å¿ã", "ç²¾æååå°è¿ä¸ç¾ä¸ç§â¦
ä¸ã¤åã®ã¨ã³ããªã§ã¯use-after-freeã«ããGOT overwriteãè¡ã£ãããC++ã«ãããvtable overwriteããã¼ããªã¼ãã¼ããã¼ã®å ´åã¨åæ§ã«è¡ããã¨ãã§ããã ããã§ã¯ãuse-after-freeã«ããC++ vtable overwriteãè¡ããã·ã§ã«ãèµ·åãã¦ã¿ãã ã¾ãDEPãæâ¦
ãã¼ãé åã«é¢é£ããèå¼±æ§ã«ã¯ããã¼ããªã¼ãã¼ããã¼ã®ã»ãã«use-after-freeã¨å¼ã°ãããã®ãããã ããã¯ãæå³ããªãæ¡ä»¶åå²ãªã©ããçºçããããã°ã©ã ã®ä¸æ´åã«ãã解æ¾æ¸ã¿ã®ãã¼ãã¡ã¢ãªã¢ãã¬ã¹ãåç §ãããç¶æ³ãåå¨ããå ´åãä»»æã®ã³ã¼ãå®â¦
ã¹ã¿ãã¯ãããã¡ãªã¼ãã¼ããã¼ãé²ãã»ãã¥ãªãã£æ©æ§ã®ä¸ã¤ã«ãSSPãããã SSPãæå¹ã«ããã¨ãé¢æ°ã®å¼ã³åºãæã«ã¹ã¿ãã¯ã«canaryã¨å¼ã°ããå¤ãç½®ããããããæ¸ãæããããã¨ãå¼·å¶çµäºããããã«ãªãã ããããä½ããã®æ¹æ³ã§canaryã®å¤ãç¥ããâ¦
Security Casual Talks 2014#2 - ãã¿ã ã»ãã¥ãªãã£åå¼·ä¼ ä»£è¡¨çãªæå·ã¢ã«ã´ãªãºã ã¨ãããã«é¢é£ãããããã¯ã«ã¤ãã¦è©±ããã CRYPT+YOU, UNDERSTAND TODAY! from inaz2 ã¿ã¤ãã«ã®å ãã¿ã¯ãã¡ããJavaãåå¼·ä¼èªä½ãä»åã¯ããã¨çæ³ã ã£ãã 次ã¯ãâ¦