Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
OneLessThing
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
OneLessThing
8y ago
“Exploit authors don’t really care about stack cookies, especially with today’s techniques like rop, jop, srop” None of those suggested techniques address stack cookies but okay, I’ll keep listening. “We can overwrite parts of the heap, the
32.
▲
by
OneLessThing
9y ago
1) ASLR: address space layout randomization 2) Yeah libc is commonly ropped against (though you'd need to check with a linux guy) 3) Yes ASLR is a compiler option (/DYANMICBASE for windows). For windows a flag exists in the PE h
33.
▲
by
OneLessThing
9y ago
Total facepalm to this comment. Does modern ASLR increase costs (time, difficulty, money, skill, etc.) necessary for exploitation and decrease benefits (privs, chances of success, etc.)? If yes, then it's a protection. Any security eng
34.
▲
by
OneLessThing
9y ago
I did security research on VLC on Windows a year or two ago. I may be remembering incorrectly, but last I recall every module was protected by ASLR. Which means that remote code execution is not likely because there is no scripting or netwo
35.
▲
by
OneLessThing
12y ago
News organizations already do this, they're called ads. You have (in theory) a clearly defined content section that is (in theory) honest, and not biased or bribed. This section earns consumers trust in the news organizations brand and
36.
▲
A Crucial Flaw in Democracy and a Five Dollar Solution [1:02:37]
(youtube.com)
1 points
by
OneLessThing
12y ago
|
0 comments
37.
▲
by
OneLessThing
12y ago
That's the thing about teaching, it depends on the student. For example, I wish someone told me to stay away from php when I began learning. My motivation was to become as effective as quickly as possible not just a casual learner or h