12.11.2012 Views

Can you still trust your network card? - Agence nationale de la ...

Can you still trust your network card? - Agence nationale de la ...

Can you still trust your network card? - Agence nationale de la ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The vulnerability Crash analysis<br />

Changing the execution flow<br />

When the RX RISC CPU is crashing, an attacker needs to:<br />

◮ find the source of the data;<br />

◮ tune it to fit her needs.<br />

Trials and errors<br />

We managed to:<br />

◮ make the username field overflow;<br />

◮ overwrite a return address in the stack with an address un<strong>de</strong>r<br />

our control.<br />

SGDSN/ANSSI – http://www.ssi.gouv.fr/<strong>trust</strong><strong>network</strong><strong>card</strong> 37/51

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!