LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-19-2004, 02:51 PM   #1
drumwell
LQ Newbie
 
Registered: Feb 2004
Posts: 3

Rep: Reputation: 0
red hat 9 stack pointer


hello all -

i posted this in the red hat forum but didn't get any response so i thought i would try here. this question is related to some strange behavior i have seen while trying to write a stack exploit on red hat 9.

in red hat 8 and other distributions, a prorgram will basically always have the same stack pointer (unless the env changes).

sp is a little program that prints out the stack pointer. three runs on a red hat 8 distro yield the following results:

bash-2.04$ ./sp
0xbffffaa8
bash-2.04$ ./sp
0xbffffaa8
bash-2.04$ ./sp
0xbffffaa8
bash-2.04$

a default red hat 9 instance exhibits totally different behavior - the stack pointer constantly changes.
[jonb@fela bufferoverflow]$ ./sp
0xbfffe5b8
[jonb@fela ]$ ./sp
0xbfffe238
[jonb@fela ]$ ./sp
0xbfffdcb8
[jonb@fela ]$ ./sp
0xbfffde38
[jonb@fela ]$ ./sp
0xbfffdfb8
[jonb@fela ]$



any idea what causes this and if it can be turned off? is this actually a kernel configuration issue?

cheers.
 
Old 02-24-2004, 12:13 PM   #2
cjcuk
Member
 
Registered: Dec 2003
Distribution: Openwall, ~LFS
Posts: 128

Rep: Reputation: 15
It may be related to ExecShield (?) if that was in Redhat 9. Just be glad they do not use PaX . The class of exploit you are trying to pull off ( or at least, the class of exploit it sounds like ) may still be fairly trivial depending on what other randomisation ExecShield incorporates and how much ( it does not appear to perform that much ).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Red Hat custom Kernel compilation mini-How-To for Red Hat 8-9 Thetargos Red Hat 431 04-13-2007 05:19 AM
Trying to locate source code for TCP/IP stack in Red Hat 9.0 pjz Linux - Software 1 06-13-2005 01:41 PM
red hat 9 stack pointer drumwell Red Hat 4 11-15-2004 02:11 PM
Red Hat does not plan to release another product in the red hat linux line... Whitehat General 5 11-03-2003 06:33 PM
Red Hat 7.2... & a modem with Red Hat 7.1 driver support rahduku Linux - Distributions 1 02-14-2002 11:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:01 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration