<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0">
<channel>
<title><![CDATA[Security docs about Format String]]></title>
<description><![CDATA[This RSS feed lists the latest security papers, articles and tutorials about format string vulnerabilities that have been added on BugHunter Security Docs - http://doc.bughunter.net/]]></description>
<link><![CDATA[http://doc.bughunter.net/format-string/]]></link>
<lastBuildDate>Mon, 07 Jul 2008 00:44:35 +0200</lastBuildDate>
<generator>http://doc.bughunter.net/</generator>
<language>en-US</language>
<copyright>http://doc.bughunter.net/</copyright>
<ttl>60</ttl>
<item>
<title><![CDATA[Bruteforcing format strings]]></title>
<link><![CDATA[http://doc.bughunter.net/format-string/bruteforce.html]]></link>
<guid isPermaLink="true"><![CDATA[http://doc.bughunter.net/format-string/bruteforce.html]]></guid>
<description><![CDATA[This text written by gera is about two tiny tricks that may help speeding up bruteforcing when exploiting format strings bugs.]]></description>
<pubdate>Sun, 08 Jan 2006 17:48:45 +0100</pubdate>
</item>
<item>
<title><![CDATA[Exploiting Format String Vulnerabilities]]></title>
<link><![CDATA[http://doc.bughunter.net/format-string/exploit-fs.html]]></link>
<guid isPermaLink="true"><![CDATA[http://doc.bughunter.net/format-string/exploit-fs.html]]></guid>
<description><![CDATA[This paper written by scut explains the nature of format string vulnerabilities. It describes how to find vulnerable C source code, and why format string vulnerabilities are more dangerous than common buffer overflows. Several exploitation techniques are detailled. After reading this article, the reader should be able to exploit almost any kind of format string vulnerability.]]></description>
<pubdate>Tue, 27 Dec 2005 22:57:28 +0100</pubdate>
</item>
<item>
<title><![CDATA[Format Bugs : What are they and How to Exploit them]]></title>
<link><![CDATA[http://doc.bughunter.net/format-string/format-bugs.html]]></link>
<guid isPermaLink="true"><![CDATA[http://doc.bughunter.net/format-string/format-bugs.html]]></guid>
<description><![CDATA[This short paper written by lamagra explains what are format bugs, and how to exploit these flaws to run arbitrary code when the attacker can control the content of the format string parameter.]]></description>
<pubdate>Tue, 27 Dec 2005 22:56:54 +0100</pubdate>
</item>
<item>
<title><![CDATA[Format Strings Exploitation Techniques]]></title>
<link><![CDATA[http://doc.bughunter.net/format-string/technique.html]]></link>
<guid isPermaLink="true"><![CDATA[http://doc.bughunter.net/format-string/technique.html]]></guid>
<description><![CDATA[This article shows various techniques that can be used in order to exploit format string vulnerabilities, through various examples.]]></description>
<pubdate>Tue, 27 Dec 2005 22:55:34 +0100</pubdate>
</item>
<item>
<title><![CDATA[How to exploit a Format Bug]]></title>
<link><![CDATA[http://doc.bughunter.net/format-string/format-bug.html]]></link>
<guid isPermaLink="true"><![CDATA[http://doc.bughunter.net/format-string/format-bug.html]]></guid>
<description><![CDATA[This paper written by kalou tries to explain how to exploit a printf(userinput) format bug, reported in some recent advisories. The approach is primary, and more precisely does not take into account any existing exploit (wu-ftpd, ...). A general knowledge of C programming and assembler is assumed throughout this article (stack issues, registers, endian storage).]]></description>
<pubdate>Tue, 27 Dec 2005 22:54:47 +0100</pubdate>
</item>
<item>
<title><![CDATA[Exploiting heap format strings (in SPARC)]]></title>
<link><![CDATA[http://doc.bughunter.net/format-string/heap-sparc.html]]></link>
<guid isPermaLink="true"><![CDATA[http://doc.bughunter.net/format-string/heap-sparc.html]]></guid>
<description><![CDATA[This paper written by riq present a way to deal with these format strings in a generic way within SPARC (and big-endian machines). It may be possible to use a similar technique for i386.]]></description>
<pubdate>Tue, 27 Dec 2005 22:52:30 +0100</pubdate>
</item>
<item>
<title><![CDATA[Format String Attack on alpha system]]></title>
<link><![CDATA[http://doc.bughunter.net/format-string/alpha.html]]></link>
<guid isPermaLink="true"><![CDATA[http://doc.bughunter.net/format-string/alpha.html]]></guid>
<description><![CDATA[This article written by Seunghyun Seo describes how format string attack can be exploited, in limited situation, on alpha system.]]></description>
<pubdate>Tue, 27 Dec 2005 22:51:52 +0100</pubdate>
</item>
</channel>
</rss>
