A video to accompany article published at http://logicdoctrine.blogspot.com, showing the mechanics of exploiting function pointers by way of a stack overflow when there is no RET on the stack. Credits to Gera for devising the exercise used in the video, the source for which you can find here:
http://community.corest.com/~gera/InsecureProgramming/abo4.html
Advanced Buffer Overflows #4 was the exercise we used. SPOILER ALERT: If you want to solve the exercise on your own, I recommend you don't watch this until you have exhausted every attempt at solving it on your own. You can do it xD
Note: Obviously, this is a local exploit using a glaringly obvious stack overflow. Needless to say, it was performed on servers which I legally own and operate. So this was done *legally*.
Link to this comment:
All Comments (0)