‹ BackHN Continuity

Thread

Data-only attacks are easier than you think (2024)

102 points · 45 comments · segfaultbuserr

  1. probably_wrong · · focus · HN ↗
    I'm missing a critical part of the explanation.

    If "the server has a memory safety bug that allows a malicious client to overflow some buffer and overwrite, for instance, the contents of the cgi_bin_path variable", then why is this a data-only attack? Instill need to overflow a buffer the "traditional" way.

    1. GoblinSlayer · · focus · HN ↗
      Yes, the author uses specialized terminology which is easy to misunderstand. They automate DEP compliant transition from buffer overflow to RCE.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.