Buffer overflow protection using stackguard and stack-smashing protection aka ProPolice

Zainon Aznan, Mohd Nor Effendy (2003) Buffer overflow protection using stackguard and stack-smashing protection aka ProPolice. [Student Project] (Unpublished)
Abstract

Buffer overflow vulnerabilities emerge and are announced frequently. Exploitation details and exploits are publicly available for interested parties. These code­based attacks allow malicious code to be executed on the vulnerable systems. This paper provides a brief introduction to buffer overflow vulnerabilities and methods of exploiting them and how the prevent these attacks using compiler tools. The tools used in this project are StackGuard from Wirex Immunix and Stack Smashing Protection aka ProPolice from IBM. A survey is made of exploits that are easily available to everyone, including the underground community. Articles on buffer overflows are reviewed, and the exploits presented are examined in terms of functionality. A platform is setup where these protections will be tested. An attempt to compile a vulnerable program is made to verify the capabilities of each compiler. Whether these compilers can detect, prevent or stop vulnerable programs from being compiled or executed

Item Details
Edit Item
Edit Item
Downloads & Files
[thumbnail of 103454.pdf]
Text
103454.pdf
Download (1MB)
Location & Physical Holdings
Digital Copy
Physical Location
Item Status
Indexing & Metrics
Download Statistics