Sinisterly
What are some low level vulns? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Network Hacking (https://sinister.li/Forum-Network-Hacking)
+--- Thread: What are some low level vulns? (/Thread-What-are-some-low-level-vulns)



What are some low level vulns? - Alan Turing - 05-07-2014

Buffer overflow
Stack Overflow
Format String Exploits
Heap Overflows

Surely there has to be more than just these, but I can never seem to find them?


RE: What are some low level vulns? - misnar - 05-07-2014

gentoo-based ROP using kernel time signatures.


RE: What are some low level vulns? - Alan Turing - 05-07-2014

(05-07-2014, 10:59 PM)misnar Wrote: gentoo-based ROP using kernel time signatures.

what the actual fuck is that


RE: What are some low level vulns? - w00t - 05-08-2014

Race conditions, improper branching, bad casting, memory leaks....


RE: What are some low level vulns? - xornull - 05-08-2014

the good one is a race hazard


RE: What are some low level vulns? - Alan Turing - 05-11-2014

(05-08-2014, 04:30 AM)xornull Wrote: the good one is a race hazard

That's race conditioning is it not?


RE: What are some low level vulns? - Merkuri - 07-18-2014

Integer overflow - Integer overflow is the result of trying to place into computer memory an integer hat is too large for the integer data type in a given system. I think there was such vulnerability in Adobe Flash before a few mouths(or years not sure).
You may like this page http://phrack.org/issues/60/10.html#article
But in my opinion the most recent vulnerability is wrong programming logic.
For example let's say that you have to check if a number is >= 0 and < 1000000 in C++ you will implement it like this:
Code:
if(number <= 0 || number > 1000000){ Do something }
But a lot of programmers make this mistake:
Code:
if(number < 0 || number > 1000000){ Do something }

Now the user can provide 0 as value, and the program may go wrong.