Tuesday, December 23, 2008

Uninitialized Memory Project

Recently Daniel Hodson and myself have been working extensively on a project regarding the automated discovery of uninitialized variable vulnerabilities. Daniel has been doing a ton of research into the area and I've been working on an old bug class which I discovered about a year ago which is related to the subject.

Daniel recently did a talk at Ruxcon 2008 on the topic which included some details of my bug class and went in depth about the intracacies of exploiting uninitialized memory vulnerabilities and methods which can be employed to discover them in an automated fashion.

Collaboratively we will be publishing a paper which will hopefully be included in the next issue of Phrack. Keep an eye out for updates regarding the project on this blog. I'll be posting more as we get all our research completed and the paper written.

10 comments:

sft said...

What happened to your paper on phrack ?:(

bannedit said...

We actually are still working on the paper. Daniel got side tracked with some other research and we are now moving towards working on the paper again. =) So hopefully the next issue we'll have it in there.

sft said...

Do you have any mail I could contact you w/ regarding that paper ?

bannedit said...

bannedit0@gmai.com

jonas said...

https://www.blogger.com/comment.g?blogID=3359952960068218647&postID=6288649862923791502&page=1&token=1563259651212

jonas said...

Nice blog!!!!!!!.
ReverseEngineering

Abhishek anand said...

Thank you for sharing an interesting and very useful article. And let me share an article about reverse engineering here I believe this is useful. Thank you.
3d scanning services in india

SixD Engineering Solutions Pvt Ltd said...

Wow it is really wonderful and awesome thus it is very much useful for me to understand many concepts and helped me a lot. it is really explainable very well and i got more information from your blog.
Reverse Engineering

Babit said...

Thanks for such a knowledgeable post.
Reverse Engineering Services in Birmingham

SixD Engineering Solutions said...

This is most informative and also this post is most user-friendly and super navigation to all posts.
Scan to BIM in California
3d Laser Scanning Services in Georgia
Reverse Engineering Services in California
Point cloud to 3D Model Reading