Buffer Overflow Attack
Buffer Overflow Attack
Buffer Overflow Attack
Simple, al ya no existir, el
Pero
seamos
negativos,
ms
que
pasara
si
sobrescribir
al
la
siguiente
instruccin
del
programa
se
ejecutar
una
nueva
de
instruccin
un
elemento
externo
del
programa original y
este
burlara
la
rutina de seguridad
del
programa,
Language/Environment
Java, Java Virtual Machine
(JVM)
Compiled or
Strongly
Direct Memory
Safe or
Interpreted
Typed
Access
Unsafe
Both
Yes
No
Safe
.NET
Both
Yes
No
Safe
Perl
Both
Yes
No
Safe
Python - interpreted
Intepreted
Yes
No
Safe
Ruby
Interpreted
Yes
No
Safe
C/C++
Compiled
No
Yes
Unsafe
Assembly
Compiled
No
Yes
Unsafe
COBOL
Compiled
Yes
No
Safe
https://www.owasp.org/index.php/Buffer_Overflows#General_Prevention_Tec
hniques
http://owasp.org,
http://www.eecis.udel.edu,
ensayos
programas
en
lenguajes
no
vulnerables
todos
Bibliografa
http://www.sans.org/readingroom/whitepapers/securecode/buffer-overflow-attackmechanism-method-prevention-386
http://www.eecis.udel.edu/~bmiller/cis459/2007s/readings/buffoverflow.html
https://www.owasp.org/index.php/Buffer_Overflows#General_Pr
evention_Techniques
http://www.tutorialspoint.com/compile_c_online.php
https://es.wikipedia.org/wiki/Robert_Tappan_Morris
http://en.citizendium.org/wiki/Canary_value