Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Devil And The Deep Blue Sea
Jon Lasser, 2002-07-17

Why Microsoft's Palladium project threatens to send Linux and open-source into exile.

Comments Mode:
The Devil And The Deep Blue Sea 2002-07-18
Anonymous (6 replies)
The Devil And The Deep Blue Sea 2002-07-18
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous
The Devil And The Deep Blue Sea 2002-07-18
Anonymous
Unbelieveable 2002-07-18
Anonymous (5 replies)
Unbelieveable 2002-07-19
Anonymous (2 replies)
Unbelieveable 2002-07-20
Anonymous
Unbelieveable 2002-07-21
Anonymous
Unbelieveable 2002-07-19
Anonymous
Unbelieveable 2002-07-19
Martin Schoch
Unbelieveable 2002-07-20
Anonymous
Unbelieveable 2002-07-20
Anonymous
The Devil And The Deep Blue Sea 2002-07-18
blacklight (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
Take a chill pill 2002-07-18
Anonymous Bastard (3 replies)
take your own advice 2002-07-19
rsullivan@art-line.com (1 replies)
Re: take your own advice 2002-07-19
Anonymous Bastard (2 replies)
Re: take your own advice 2002-07-19
Anonymous (2 replies)
happy x86 processor world? riiiiight... 2002-07-19
Anonymous (1 replies)
Re: take your own advice 2002-07-21
Anonymous
Re: take your own advice 2002-07-19
Anonymous
Re: Take a chill pill 2002-07-19
Jm4n
Take a chill pill 2002-07-21
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous (1 replies)
OSS version of Palladium 2002-07-20
Abri
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
SkyLeach
Palladium and buffer overflows 2002-07-19
Anonymous (6 replies)
Palladium and buffer overflows 2002-07-19
Anonymous
Palladium and buffer overflows 2002-07-19
Anonymous
A buffer overflow is a runtime event.

Here's an example: The developer has only allocated 32 bytes for a buffer. The attacker manages to stuff 64 bytes into it. Those 64 bytes are copied into the storage space allocated for the buffer. The "extra" 32 bytes don't just disappear: they get placed in the memory that follows the buffer.

So whatever was assigned to use the memory area just after the buffer got stomped on. This might be storage for variables, machine code... whatever. What does this do? That depends on how clever the attacker is.

But the key here is that the program in *memory* is being messed with - after it's been verified as trustworthy. So the buffer overflow attack can't be stopped by Palladium.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/96/15724#15724
Palladium and buffer overflows 2002-07-20
bufferoverwhelmed
Palladium and buffer overflows 2002-07-20
Anonymous
Palladium and buffer overflows 2002-07-21
Anonymous
Pride goeth before a Fall 2002-07-19
Anonymous
No evidence for these claims 2002-07-19
Tamperbell (2 replies)
No evidence for these claims 2002-07-22
Anonymous
No evidence for these claims 2002-07-23
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
Alternate hardware 2002-07-20
Anonymous
The Devil And The Deep Blue Sea 2002-07-20
Anonymous
THE DEVIL AND THE DEEP BLUE SEE 2002-07-20
NSS ( Network Ssecurity Systems)
It's all about trust 2002-07-20
Anonymous
The Devil And The Deep Blue Sea 2002-07-21
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous
The Devil And The Deep Blue Sea 2002-07-23
Anonymous (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
Copyright and Anti-piracy laws 2002-07-29
Anonymous
It is time for "security enhanced linux" to be put on the front burner NOW! 2002-07-29
100% of distros should be 100% SE Linux







 

Privacy Statement
Copyright 2009, SecurityFocus