|
1. Shacham, H., The Geometry of Innocent Flesh on the Bone: Return-into-libc without Function Calls (on the x86). Ccs'07: Proceedings of the 14th Acm Conference on Computer and Communications Security, 2007: p. 552-561. 2. Team, P. Pax address space layout randomization. Available from: http://pax.grsecurity.net/docs/aslr.txt. 3. Payer, M., Too much PIE is bad for performance. 2012. 4. Huang, S.K., et al. CRAX: Software Crash Analysis for Automatic Exploit Generation by Modeling Attacks as Symbolic Continuations. in Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on. 2012. IEEE. 5. 黃世昆, et al., 自動脅迫產生器發展現況與威脅分析. 資訊安全通訊, 2012. 18(3): p. 88-100. 6. Chipounov, V., V. Kuznetsov, and G. Candea, The S2E platform: Design, implementation, and applications. ACM Transactions on Computer Systems (TOCS), 2012. 30(1): p. 2. 7. Bellard, F. QEMU, a Fast and Portable Dynamic Translator. in USENIX Annual Technical Conference, FREENIX Track. 2005. 8. Maynor, D., Metasploit toolkit for penetration testing, exploit development, and vulnerability research. 2011: Elsevier. 9. c0ntex. Bypassing non-executable-stack during exploitation using return-to-libc. Available from: http://css.csail.mit.edu/6.858/2014/readings/return-to-libc.pdf. 10. Du, W. Return-to-libc Attack Lab. 2007; Available from: http://www.cis.syr.edu/~wedu/seed/Labs/Vulnerability/Return_to_libc/Return_to_libc.pdf. 11. King, J.C., Symbolic execution and program testing. Communications of the ACM, 1976. 19(7): p. 385-394. 12. Păsăreanu, C.S. and W. Visser, A survey of new trends in symbolic execution for software testing and analysis. International journal on software tools for technology transfer, 2009. 11(4): p. 339-353. 13. Sen, K. Concolic testing. in Proceedings of the twenty-second IEEE/ACM international conference on Automated software engineering. 2007. ACM. 14. Salwan, J. ROPgadget. Available from: https://github.com/JonathanSalwan/ROPgadget. 15. Schwartz, E.J., T. Avgerinos, and D. Brumley. Q: Exploit Hardening Made Easy. in USENIX Security Symposium. 2011. 16. Avgerinos, T., et al. AEG: Automatic Exploit Generation. in NDSS. 2011. 17. Brumley, D., et al. Automatic patch-based exploit generation is possible: Techniques and implications. in Security and Privacy, 2008. SP 2008. IEEE Symposium on. 2008. IEEE. 18. Chen, P., et al., DROP: Detecting return-oriented programming malicious code, in Information Systems Security. 2009, Springer. p. 163-177. 19. Cao, J., et al., LGadget: ROP Exploit based on Long Instruction Sequences. 2013. 20. Dullien, T., T. Kornau, and R.-P. Weinmann. A Framework for Automated Architecture-Independent Gadget Search. in WOOT. 2010. 21. Kornau, T., Return oriented programming for the ARM architecture. Master's thesis, Ruhr-Universitat Bochum, 2010. 22. Roemer, R.G., Finding the bad in good code: Automated return-oriented programming exploit discovery. 2009. 23. Security, O. Metasploit Meterpreter. Available from: http://www.offensive-security.com/metasploit-unleashed/About_Meterpreter. 24. Graeber, M. PowerSploit - A PowerShell Post-Exploitation Framework. Available from: https://github.com/mattifestation/PowerSploit. 25. Campbell, C. PowerSploit + Metasploit = Shells. Available from: http://obscuresecurity.blogspot.tw/2013/03/powersploit-metasploit-shells.html. 26. Nguyen Anh Quynh, C., Capstone: Next-Gen Disassembly Framework. 2014: Blackhat USA. 27. Burt, G.L. Linux System Call Table. 2004; Available from: http://docs.cs.up.ac.za/programming/asm/derick_tut/syscalls.html.
|