[framework] mcafee Entercept

Weston, David G. DAVID.G.WESTON at saic.com
Tue Oct 30 10:22:01 CDT 2007


Hi All,
  Has anyone had luck with various payloads and mcafee entercept?
Theres a paper out of the Naval War college
http://www.nps.navy.mil/Content/CS/ncrowe/oldstudents/labbe_thesis.htm
where the author test various exploits from metasploit/core vs mcafee
entercept and cisco security agent.  Does anyone have any experience in
this area?  There's a paper in Phrack 62 about evading third party
buffer overflow protection and I have had some success with the
technique of using a return address in the process space marked
read-only for the final stack frame but does anyone having tricks to add
to this?

Thanks,
Dave



More information about the framework mailing list