期刊文献+

缓冲区溢出漏洞利用研究 被引量:2

On Vulnerability Exploiting of Buffer Overflow
下载PDF
导出
摘要 远程缓冲区溢出漏洞是网络安全领域最严重的安全漏洞。而远程过程调用广泛应用于分布式环境中,是发起远程缓冲区溢出攻击的常见手段。首先,阐述缓冲区溢出的基本原理,给出windows下利用远程过程调用发起远程缓冲区溢出攻击的一般方法和主要流程,通过一个缓冲区溢出漏洞利用的实例,说明攻击流程和分析方法的有效性,为如何在网络环境下有效防范缓冲区溢出漏洞利用提供指导。 The remote buffer overflow vulnerability is the most serious security vulnerability in network security domain. Remote procedure call has been widely applied to distribute computing. Thus, RPC is a common technology which is used in vulnerability exploiting of buffer overflow. Firstly, the principles and technology about buffer overflow exploiting are described, and then methods of vulnerability analysis and the process of vulnerability exploiting by RPC are provid- ed, because most of buffer overflows exploiting belongs to remote attacking. Finally, an instance of vulnerability exploiting is provided to verify the validity of exploiting process and instruct how to prevent buffer overflow exploiting.
作者 冯潇
出处 《北京联合大学学报》 CAS 2009年第2期7-10,共4页 Journal of Beijing Union University
关键词 缓冲区溢出 恶意代码 漏洞利用 远程过程调用 逆向技术 buffer overflow shellcode vulnerability exploiting RPC Reversing technology
  • 相关文献

参考文献5

二级参考文献18

  • 1邱晓鹏,张玉清,冯登国.缓冲区溢出攻击代码的分析研究[J].计算机工程与应用,2005,41(18):134-135. 被引量:11
  • 2于晗,孙龙霞,黄承夏.基于Windows缓冲区溢出漏洞的植入型木马研究[J].信息安全与通信保密,2005(7):248-252. 被引量:4
  • 3Aleph One.Smashing the Stack for Fun and Profit[J].Phrack,1996,7(49).
  • 4Matt Conover.w00w00 on Heap Overflows[EB/OL].http://www.w00w00.org/articles.html,1999.
  • 5John Wilander,Mariam Kamkar.A Comparison of Publicly Available Tools for Dynamic Buffer Overflow Prevention[C].The 10th Network and Distributed System Security Symposium,2003.
  • 6aXis.缓冲区溢出笔记之-Stack溢出[EB/OL].http://www.ph4nt0m.net,2004.
  • 7Taeho Oh.Advanced Buffer Overflow Exploit[EB/OL].http://postech.edu/~ohhara,2004-09.
  • 8Compaq.Compaq C for Linux[EB/OL].http:// www.unix.digital.com/linux/compaq_c/,1999.
  • 9Richard Jones,Paul Kelly.Bounds Checking for C[EB/OL].http://www-ala.doc.ic.ac.uk/ phjk/ BoundsChecking.html,1995.
  • 10Crispin Cowan,Calton Pu,Dave Maier,et al.StackGuard:Automatic Adaptive Detection and Prevention of Buffer Overflow Attacks[C].The 7th USENIX Security Conference,1998.63-77.

共引文献12

同被引文献2

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部