{"id":201,"date":"2007-07-23T15:32:38","date_gmt":"2007-07-23T23:32:38","guid":{"rendered":"http:\/\/www.evardsson.com\/blog\/2007\/07\/23\/new-class-of-exploits-dangling-pointers\/"},"modified":"2007-07-23T15:32:40","modified_gmt":"2007-07-23T23:32:40","slug":"new-class-of-exploits-dangling-pointers","status":"publish","type":"post","link":"https:\/\/www.evardsson.com\/blog\/2007\/07\/23\/new-class-of-exploits-dangling-pointers\/","title":{"rendered":"New Class of Exploits: Dangling Pointers"},"content":{"rendered":"<p>While <a href=\"http:\/\/en.wikipedia.org\/wiki\/Dangling_pointer\">dangling pointers<\/a> are a common coding error (especially in C++) there has previously been no way known to exploit them. In fact, they were generally considered a quality control issue rather than a security issue. That is all set to change. According to an <a href=\"http:\/\/searchsecurity.techtarget.com\/originalContent\/0,289142,sid14_gci1265116,00.html\">article today from SearchSecurity<\/a> Jonathan Afek and Adi Sharabani of <a href=\"http:\/\/www.watchfire.com\/\">Watchfire Inc<\/a> have uncovered a way to exploit generic dangling pointers to run shell code on a server in much the same fashion as buffer overflows. According to Danny Allen (also of Watchfire) this technique can be used on any application with dangling pointers.<\/p>\n<p>Afek will be giving a presentation on the technique in August at the <a href=\"http:\/\/www.blackhat.com\/html\/bh-usa-07\/bh-usa-07-index.html\">Black Hat Briefings<\/a> in Las Vegas.<\/p>\n<div style=\"visibility: hidden;\" title=\"1185233322475\" id=\"_booktextmark_tab_id_\"><\/div>\n<div style=\"visibility: hidden;\" title=\"1185233697655\" id=\"_booktextmark_tab_id_\"><\/div>\n<p>Technorati Tags: <a class=\"performancingtags\" href=\"http:\/\/technorati.com\/tag\/security\" rel=\"tag\">security<\/a>, <a class=\"performancingtags\" href=\"http:\/\/technorati.com\/tag\/dangling%20pointers\" rel=\"tag\">dangling pointers<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While dangling pointers are a common coding error (especially in C++) there has previously been no way known to exploit them. In fact, they were generally considered a quality control issue rather than a security &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[11,10],"tags":[148,147],"class_list":["post-201","post","type-post","status-publish","format-standard","hentry","category-development","category-security","tag-development","tag-security"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pxT7i-3f","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/posts\/201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/comments?post=201"}],"version-history":[{"count":0,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/posts\/201\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/media?parent=201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/categories?post=201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/tags?post=201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}