Discussion on buffer overflow prevention issues


What an attacker is looking for:

stack overflows
data segment overflows
GOT/PLT overwrite
jumping to data that he can execute
4 byte modification possibility
4 byte read possibility?
perhaps can still find system code to jump to

We want to disrupt as many of these as possible