Document information
- University
- Politecnico di Milano
- Degree programme
- Computer Engineering
- Subject
- Computer Security
- Academic year
- 2014-2015
- Classification
- Exam · Full exam
- Content
- Exam paper only
- Original format
- Text
- Searchable text
Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Privacy and Security Exam Como Feb 25, 2015 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Instructions ● The exam is composed of 9 pages. ● Just as a
Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Privacy and Security Exam Como Feb 25, 2015 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Instructions ● The exam is composed of 9 pages. ● Just as a
Import quality: text was extracted directly from the original document.
Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.
Privacy and Security Exam Como Feb 25, 2015 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Instructions ● The exam is composed of 9 pages. ● Just as a cross check, tell us whether you have completed the homeworks, by putting an "X" mark appropriately. ● The exam is "closed books". Please put away in a nonsuspicious place (i.e. not below the desk) any note, book, or similar. You will be expelled if, at any time, if you do not follow this rule. ● You are not allowed to communicate with other students, and you will be expelled from the exam if you do. ● Shut down and store electronic devices. They will be subject to inspection if found and you may be expelled if you are found using one. ● Please answer within the allowed space. Schemes are good, short answers are recommended. ● You can write in pen or pencil, any color, but avoid writing in red. ● No extra paper is allowed. ● The answers must be written exclusively in the space provided below the questions. DRAFT COPY WITH SOLUTIONS 1 of 9 Question 1 (6 points) You are writing an exploit for a software vulnerable to a stack overflow. You have enough space to write shellcode in the stack: 1. Draw the stack state right before the RET instruction at the end of the function during exploitation (show where the head of the stack is, and where the saved return address points to) 2. Now, assume that a canary protection is used. It generates a random canary and stores it at a fixed location in memory. Explain what you need to do to successfully exploit the target: To proceed exploiting since the canary is at a fixed memory location we need a memory leak that allows us to read it somehow. 3. Suppose…
First page of the document.