Topic: "Buffer Overflows, Format Overflows, ..." (page 1 of 1)

1
Author Post
theblacksheep
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
Hi people,

if ou are interested in creating some challenges where you have to overflow buffers or anything else that has to do with exploiting an application just post a message here.
private message EMail Website
Corso
groupmastergroupmastergroupmastergroupmastergroupmaster
I'm interested on that :)

But how could we test the solution? should the admins revise it by hand?
private message
theblacksheep
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
yeah. the solution hase to be send to the group who is in charge of this challenge section and they have to check it and also set the user to solved. do it would be awesome if at least 3 or 4 people would work together.
Edited by theblacksheep on 10.02.2004 21:54:22
private message EMail Website
Corso
groupmastergroupmastergroupmastergroupmastergroupmaster
humm it sounds good. but we should wait to know how many people is interested on buffer overflows. I could make some challenges for this section, i think.
private message
obiwan
groupmastergroupmastergroupmastergroupmaster
Hi
I'm interested on such challs but in fact i have no idea how to do something like this.
It also seems to be very difficult to make a chall for buffer overflow.
1. you must make a process that runs on a Server otherwise it would be only a crackit.
2. this process must run in a sandbox and you have to find a provider who will allow this or you need a dedicated server.
3. you have to limit the actions the exploit can do otherwise you can forget your server
4. a tutorial how bufferoverflows can be used to inject a program would be nice. I think there are very few people who know how to do this
private message
iloveallison
groupmastergroupmastergroupmaster
um i already have a shell on this site
http://www.celuloza.ro/

if TBS wants it you can use it just message me and i will give you the username and pw
private message
HexFortyFive
groupmaster
wargames.unix.se
these guys have a whole bunch of different of these 'sandboxed' linux wargames. they seem to be down ATM, but you should check it out when you get a chance.
private message Website
Corso
groupmastergroupmastergroupmastergroupmastergroupmaster
Humm cool site. But running a wargame like that is so difficult by now (i think). Exploiting vulnerable code i think is easier :)

See you,
Corso

PS: Why in the hell im here at 6.48 am? :S
private message

Topic: "Buffer Overflows, Format Overflows, ..." (page 1 of 1)

1