Create an exploit in just 20 minutes
Openservice.com had a post over the weekend pointing to a flash movie that shows how to use IDA plus the bin diff plugin from Sabre Security to analyze a patch and find where a vulnerability has been fixed in less than half an hour.
I have been talking about how easy it is to do this for a while now, but I never saw someone show it so eliquently in a simple movie like this. This is WHY it doesn't matter if you have access to the code or not.
Want to learn more on how to do this sort of analysis? Pick up a copy of Exploiting Software: How to Break Code and learn about it yourself. You can read my review of this book here.
Posted by SilverStr at July 11, 2005 01:25 PM
| TrackBack