[Full-disclosure] Hikaru
Ben
comsatcat at earthlink.net
Sat Dec 22 01:36:44 GMT 2007
All,
I read a paper last night titled "The Geometry of Innocent Flesh on the Bone" (http://www.cse.ucsd.edu/~hovav/). It described a technique similar to return-into-libc. The utility I'm attaching (hikaru) implements an automated binary analysis to determine possible instructions (gadgets, per the article) that can be used for this exploitation method.
See the included README for detailed usage instructions.
- Ben
Full-Disclosure is hosted and sponsored by Secunia.