Coolio10
October 31st, 2007, 07:29 PM
Well i noticed aigle's post about threatfire and wondering what you all think about buffer overflow protection. Is it needed? Have you encountered it?
Well two products that are suppose to protect against it are threatfire and comodo memory guardian which is being kept quiet in the beta area.
Comodo Memory Guardian was made to protect only against them. It will also be eventually integrated into the firewall.
Like to see some feedback about it.
Sorry about the big pictures. Taken right from the developer.
They are pics of CMG blocking the new vista .ani vulnerability and the yahoo messenger exploit.
http://www.wilderssecurity.com/attachment.php?attachmentid=194724&d=1193872801
http://www.wilderssecurity.com/attachment.php?attachmentid=194725&d=1193872801
-{ Quote: "Comodo Memory Gurdian is a buffer overflow detecion and protection tool which provides the ultimate defense against one of the most serious and common attack types on the Internet.
What is a Buffer Overflow attack?
-------------------------------------
...excerpt from http://en.wikipedia.org/wiki/Buffer_overflow
"
In computer security and programming, a buffer overflow, or buffer overrun, is a programming error which may result in a memory access exception and program termination, or in the event of the user being malicious, a possible breach of system security.
A buffer overflow is an anomalous condition where a process attempts to store data beyond the boundaries of a fixed-length buffer. The result is that the extra data overwrites adjacent memory locations. The overwritten data may include other buffers, variables and program flow data and may cause a process to crash or produce incorrect results. They can be triggered by inputs specifically designed to execute malicious code or to make the program operate in an unintended way. As such, buffer overflows cause many software vulnerabilities and form the basis of many exploits. Sufficient bounds checking by either the programmer or the compiler can prevent buffer overflows."
Features :
* Detection of Buffer Overflows which occur in the STACK memory,
* Detection of Buffer Overflows which occur in the HEAP memory,
* Detection of ret2libc attacks,
* Full 32 bit and 64 bit Support,
Important Note : This is a BETA product and is intended only for the users who would like to test the product and provide us some feedback. It may contain major bugs which may cause your system to be unstable or cause permanent data loss. Please do not instal this software into a production machine or distribute it." }-
Well two products that are suppose to protect against it are threatfire and comodo memory guardian which is being kept quiet in the beta area.
Comodo Memory Guardian was made to protect only against them. It will also be eventually integrated into the firewall.
Like to see some feedback about it.
Sorry about the big pictures. Taken right from the developer.
They are pics of CMG blocking the new vista .ani vulnerability and the yahoo messenger exploit.
http://www.wilderssecurity.com/attachment.php?attachmentid=194724&d=1193872801
http://www.wilderssecurity.com/attachment.php?attachmentid=194725&d=1193872801
-{ Quote: "Comodo Memory Gurdian is a buffer overflow detecion and protection tool which provides the ultimate defense against one of the most serious and common attack types on the Internet.
What is a Buffer Overflow attack?
-------------------------------------
...excerpt from http://en.wikipedia.org/wiki/Buffer_overflow
"
In computer security and programming, a buffer overflow, or buffer overrun, is a programming error which may result in a memory access exception and program termination, or in the event of the user being malicious, a possible breach of system security.
A buffer overflow is an anomalous condition where a process attempts to store data beyond the boundaries of a fixed-length buffer. The result is that the extra data overwrites adjacent memory locations. The overwritten data may include other buffers, variables and program flow data and may cause a process to crash or produce incorrect results. They can be triggered by inputs specifically designed to execute malicious code or to make the program operate in an unintended way. As such, buffer overflows cause many software vulnerabilities and form the basis of many exploits. Sufficient bounds checking by either the programmer or the compiler can prevent buffer overflows."
Features :
* Detection of Buffer Overflows which occur in the STACK memory,
* Detection of Buffer Overflows which occur in the HEAP memory,
* Detection of ret2libc attacks,
* Full 32 bit and 64 bit Support,
Important Note : This is a BETA product and is intended only for the users who would like to test the product and provide us some feedback. It may contain major bugs which may cause your system to be unstable or cause permanent data loss. Please do not instal this software into a production machine or distribute it." }-