Saturday, June 27, 2015

Software Security

1. Three of the following are classic security properties:
  • Confidentiality
  • Integrity
  • Availability
2. Morris Worm is the first Buffer Overflow Attack.
3. The stack is memory for storing Local Variables
4. Why is it that the compiler does not know the absolute address of a local variable?
  • As a stack-allocated variable, it could have different addresses depending on who called the function
5. When does a buffer overflow occur?
  • When a pointer is used to access memory not allocated to it 
6. How does a buffer overflow on the stack facilitate running attacker-injected code?
  • By overwriting the return address to point to the location of that code
The Heart of the Matter course
7. Nop Sled: It is a sequence of nops preceding injected shellcode, useful when the return address is unknown. The sequence nop instructs "sleds" the instruction pointer to the actual attacker code of interest
8. Exploitation of the Heartbleed bug permits a read outside bounds of a buffer.
9. Anti-virus scanners would not have found an exploitation of Heartbleed because
Anti-virus scanners tend to look for viruses and other malicious code, but Heartbleed exploits steal secrets without injecting any code
10. An integer overflow occurs when an integer is used to access a buffer outside of the buffer's bounds.

4 comments:

  1. Nice blog.. thanks author for sharing... please visit once at http://www.qosnetworking.com/ 

    ReplyDelete
  2. Hello everyone..

    I'm selling fresh leads. Details in leads are:

    Full name
    SSN
    DOB
    Phone Numbers
    Address
    City
    State
    Zip
    Residential Status
    Account Number
    DL number
    Emails

    All leads are genuine, fresh & generated by spaming, I Will provide you samples for checking if u want.

    Dealing in almost all types of leads.

    SSN Leads
    Dead Fullz
    Premium Leads
    Mortgage Leads
    Bank Account Leads
    Employee Leads
    Business Leads
    Home Owners Leads
    DL Leads
    Emails Leads
    Phone Numbers Leads

    Each lead will b cost $1.

    Also cvv Fullz available track 1 & track 2 with pin.

    Interested person contact, scammers stay away, sampling is free of cost.

    email > leads.sellers1212@gmail.com
    Whatsapp > +923172721122
    Telegram > @leadsupplier
    ICQ > 752822040

    ReplyDelete