-

Twitter avatar for @fdfalcon
Francisco Falcon @fdfalcon
Lured by @4Dgifts, I took a look at the new stack-based buffer overflow in FreeBSD's ping when processing ICMP responses (CVE-2022-23093): freebsd.org/security/advis…

TL;DR: bug doesn't seem exploitable on FreeBSD 13.1 x64, thanks to the stack layout created by variable reordering.

Image

-

-

I stumbled on @zwol@hackers.town 's excellent blog post "I Didn’t Learn Unix By Reading All The Manpages:" https://www.owlfolio.org/research/i-didnt-learn-unix-by-reading-all-the-manpages/

I could not agree more. Manpages are excellent references, but they are absolutely not educational. So, how do you learn? Tutorials, textbooks, and most importantly, tinkering with stuff until it works.

-

-

-

-

Don't miss what's next. Subscribe to the grugq's newsletter: