On 4/2/07, <b class="gmail_sendername">Larry Seltzer</b> &lt;<a href="mailto:Larry@larryseltzer.com">Larry@larryseltzer.com</a>&gt; wrote:<div><span class="gmail_quote"></span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
LS&gt;Heap spraying implies running code in the heap,<br>JA&gt;Actually, um.. no.. it doesn&#39;t<br><br>My understanding of heap spraying comes from<br><a href="http://blogs.securiteam.com/index.php/archives/638">http://blogs.securiteam.com/index.php/archives/638
</a>: &quot;...SkyLined&#39;s heap<br>spraying techqniue<br>(<a href="http://sf-freedom.blogspot.com/2006/07/heap-spraying-internet-exploiter">http://sf-freedom.blogspot.com/2006/07/heap-spraying-internet-exploiter</a><br>
.html) (the concept of this technique is that you inject the nop +<br>shellcode into the heap memory and use some method to trick the eip jump<br>into that heap ...&quot;<br><br>Sure sounds like running code in the heap to me.
</blockquote><div><br><br>&quot;Heap spraying&quot; is filling the heap with controllable data... This is simply allocating things in the heap. NOT running code.<br><br>You are trying to say that once you jump into that code via some exploit (NOT part of the heap spraying technique itself) THEN you are &quot;running code in the heap&quot;.
<br><br><br></div><br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">JA&gt;How do you get to be in that position? Lot&#39;s of buzzword-tossing I&#39;d
<br>have to guess.<br><br>Fuck you too.<br><br>Larry Seltzer<br>eWEEK.com Security Center Editor<br><a href="http://security.eweek.com/">http://security.eweek.com/</a> &lt;blocked::<a href="http://security.eweek.com/">http://security.eweek.com/
</a>&gt;<br><a href="http://blog.eweek.com/blogs/larry%5Fseltzer/">http://blog.eweek.com/blogs/larry%5Fseltzer/</a><br>&lt;<a href="http://blog.eweek.com/blogs/larry_seltzer/">http://blog.eweek.com/blogs/larry_seltzer/</a>
&gt;<br>&lt;<a href="http://blog.ziffdavis.com/seltzer">http://blog.ziffdavis.com/seltzer</a>&gt;<br>Contributing Editor, PC Magazine<br><a href="mailto:larryseltzer@ziffdavis.com">larryseltzer@ziffdavis.com</a><br></blockquote>
</div><br>