{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,26]],"date-time":"2026-07-26T06:25:10Z","timestamp":1785047110795,"version":"3.55.0"},"reference-count":64,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2012,3,1]],"date-time":"2012-03-01T00:00:00Z","timestamp":1330560000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-0433668CNS-0831532"],"award-info":[{"award-number":["CNS-0433668CNS-0831532"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2012,3]]},"abstract":"<jats:p>\n            We introduce\n            <jats:italic>return-oriented programming<\/jats:italic>\n            , a technique by which an attacker can induce arbitrary behavior in a program whose control flow he has diverted, without injecting any code. A return-oriented program chains together short instruction sequences already present in a program\u2019s address space, each of which ends in a \u201creturn\u201d instruction.\n          <\/jats:p>\n          <jats:p>Return-oriented programming defeats the W\u2295X protections recently deployed by Microsoft, Intel, and AMD; in this context, it can be seen as a generalization of traditional return-into-libc attacks. But the threat is more general. Return-oriented programming is readily exploitable on multiple architectures and systems. It also bypasses an entire category of security measures---those that seek to prevent malicious computation by preventing the execution of malicious code.<\/jats:p>\n          <jats:p>To demonstrate the wide applicability of return-oriented programming, we construct a Turing-complete set of building blocks called gadgets using the standard C libraries of two very different architectures: Linux\/x86 and Solaris\/SPARC. To demonstrate the power of return-oriented programming, we present a high-level, general-purpose language for describing return-oriented exploits and a compiler that translates it to gadgets.<\/jats:p>","DOI":"10.1145\/2133375.2133377","type":"journal-article","created":{"date-parts":[[2012,3,27]],"date-time":"2012-03-27T15:17:31Z","timestamp":1332861451000},"page":"1-34","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":387,"title":["Return-Oriented Programming"],"prefix":"10.1145","volume":"15","author":[{"given":"Ryan","family":"Roemer","sequence":"first","affiliation":[{"name":"University of California, San Diego"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Erik","family":"Buchanan","sequence":"additional","affiliation":[{"name":"University of California, San Diego"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hovav","family":"Shacham","sequence":"additional","affiliation":[{"name":"University of California, San Diego"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stefan","family":"Savage","sequence":"additional","affiliation":[{"name":"University of California, San Diego"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2012,3]]},"reference":[{"key":"e_1_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_2_2_2_1","first-page":"14","article-title":"Smashing the stack for fun and profit","volume":"49","author":"Aleph One","year":"1996","unstructured":"Aleph One . 1996 . Smashing the stack for fun and profit . Phrack Mag. 49 , 14 . http:\/\/www.phrack.org\/archives\/49\/p49_0x0e_Smashing&percnt;20The&percnt;20Stack&percnt;20For&percnt;20Fun&percnt;20And&percnt;20Profit_by_Aleph1.txt. Aleph One. 1996. Smashing the stack for fun and profit. Phrack Mag. 49, 14. http:\/\/www.phrack.org\/archives\/49\/p49_0x0e_Smashing&percnt;20The&percnt;20Stack&percnt;20For&percnt;20Fun&percnt;20And&percnt;20Profit_by_Aleph1.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_3_1","first-page":"9","article-title":"Once upon a free()","volume":"57","author":"Anonymous","year":"2001","unstructured":"Anonymous . 2001 . Once upon a free() .... Phrack Mag. 57 , 9 . http:\/\/www.phrack.org\/archives\/57\/p57_0x09_Once&percnt;20upon&percnt;20a&percnt;20free()_by_&percnt;anonymous&percnt;20author.txt. Anonymous. 2001. Once upon a free().... Phrack Mag. 57, 9. http:\/\/www.phrack.org\/archives\/57\/p57_0x09_Once&percnt;20upon&percnt;20a&percnt;20free()_by_&percnt;anonymous&percnt;20author.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1053283.1053286"},{"key":"e_1_2_2_5_1","volume-title":"Proceedings of the USENIX Workshop on Offensive Technologies (WOOT\u201910)","author":"Blazakis D.","year":"2010","unstructured":"Blazakis , D. 2010 . Interpreter exploitation . In Proceedings of the USENIX Workshop on Offensive Technologies (WOOT\u201910) . H. Shacham and C. Miller Eds., USENIX. Blazakis, D. 2010. Interpreter exploitation. In Proceedings of the USENIX Workshop on Offensive Technologies (WOOT\u201910). H. Shacham and C. Miller Eds., USENIX."},{"key":"e_1_2_2_6_1","first-page":"10","article-title":"Basic integer overflows","volume":"60","year":"2002","unstructured":"blexim. 2002 . Basic integer overflows . Phrack Mag. 60 , 10 . http:\/\/www.phrack.org\/archives\/60\/p60_0x0a_Basic&percnt;20Integer&percnt;20Overflows_&percnt;by_blexim.txt. blexim. 2002. Basic integer overflows. Phrack Mag. 60, 10. http:\/\/www.phrack.org\/archives\/60\/p60_0x0a_Basic&percnt;20Integer&percnt;20Overflows_&percnt;by_blexim.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455776"},{"key":"e_1_2_2_8_1","first-page":"5","article-title":"Bypassing StackGuard and StackShield","volume":"56","author":"Bulba","year":"2000","unstructured":"Bulba and Kil3r. 2000 . Bypassing StackGuard and StackShield . Phrack Mag. 56 , 5 . http:\/\/www.phrack.org\/archives\/56\/p56_0x05_Bypassing&percnt;20StackGuard&percnt;20and&percnt;20StackShield_by_Kil3r&percnt;20&&percnt;&percnt;20Bulba.txt. Bulba and Kil3r. 2000. Bypassing StackGuard and StackShield. Phrack Mag. 56, 5. http:\/\/www.phrack.org\/archives\/56\/p56_0x05_Bypassing&percnt;20StackGuard&percnt;20and&percnt;20StackShield_by_Kil3r&percnt;20&&percnt;&percnt;20Bulba.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_9_1","volume-title":"Proceedings of the Electronic Voting Technology Workshop\/Workshop on Trustworthy Elections (EVT\/WOTE\u201909)","author":"Checkoway S.","unstructured":"Checkoway , S. , Feldman , A. J. , Kantor , B. , Halderman , J. A. , Felten , E. W. , and Shacham , H . 2009. Can DREs provide long-lasting security? The case of return-oriented programming and the AVC advantage . In Proceedings of the Electronic Voting Technology Workshop\/Workshop on Trustworthy Elections (EVT\/WOTE\u201909) . D. Jefferson, J. L. Hall, and T. Moran Eds., USENIX\/ACCURATE\/IAVoSS. Checkoway, S., Feldman, A. J., Kantor, B., Halderman, J. A., Felten, E. W., and Shacham, H. 2009. Can DREs provide long-lasting security? The case of return-oriented programming and the AVC advantage. In Proceedings of the Electronic Voting Technology Workshop\/Workshop on Trustworthy Elections (EVT\/WOTE\u201909). D. Jefferson, J. L. Hall, and T. Moran Eds., USENIX\/ACCURATE\/IAVoSS."},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866370"},{"key":"e_1_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10772-6_13"},{"key":"e_1_2_2_12_1","volume-title":"Proceedings of the USENIX Security Symposium. A. Rubin Ed., 63--78","author":"Cowan C.","unstructured":"Cowan , C. , Pu , C. , Maier , D. , Hinton , H. , Bakke , P. , Beattie , S. , Grier , A. , Wagle , P. , and Zhang , Q . 1998. StackGuard: Automatic detection and prevention of buffer-overflow attacks . In Proceedings of the USENIX Security Symposium. A. Rubin Ed., 63--78 . Cowan, C., Pu, C., Maier, D., Hinton, H., Bakke, P., Beattie, S., Grier, A., Wagle, P., and Zhang, Q. 1998. StackGuard: Automatic detection and prevention of buffer-overflow attacks. In Proceedings of the USENIX Security Symposium. A. Rubin Ed., 63--78."},{"key":"e_1_2_2_13_1","unstructured":"Dai Zovi D. 2010. Return-oriented exploitation. Black Hat (Presentation slides). https:\/\/media.blackhat.com\/bh-us-10\/presentations\/ Zovi\/BlackHat-USA-2010-DaiZovi-Return-Oriented-Exploitation-slides.pdf. Dai Zovi D. 2010. Return-oriented exploitation. Black Hat (Presentation slides). https:\/\/media.blackhat.com\/bh-us-10\/presentations\/ Zovi\/BlackHat-USA-2010-DaiZovi-Return-Oriented-Exploitation-slides.pdf."},{"key":"e_1_2_2_14_1","first-page":"15","article-title":"Win32 buffer overflows (location, exploitation, and prevention)","volume":"55","year":"1999","unstructured":"dark spyrit. 1999 . Win32 buffer overflows (location, exploitation, and prevention) . Phrack Mag. 55 , 15 . http:\/\/www.phrack.org\/archives\/55\/p55_0x0f_Win32&percnt;20Buffer&percnt;20Overflows..._by_dark&percnt;20spyrit.txt. dark spyrit. 1999. Win32 buffer overflows (location, exploitation, and prevention). Phrack Mag. 55, 15. http:\/\/www.phrack.org\/archives\/55\/p55_0x0f_Win32&percnt;20Buffer&percnt;20Overflows..._by_dark&percnt;20spyrit.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655108.1655117"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966920"},{"key":"e_1_2_2_17_1","volume-title":"Proceedings of the USENIX Workshop on Offensive Technologies (WOOT). H. Shacham and C. Miller Eds., USENIX.","author":"Dullien T.","unstructured":"Dullien , T. , Kornau , T. , and Weinmann , R . -P. 2010. A framework for automated architecture-independent gadget search . In Proceedings of the USENIX Workshop on Offensive Technologies (WOOT). H. Shacham and C. Miller Eds., USENIX. Dullien, T., Kornau, T., and Weinmann, R.-P. 2010. A framework for automated architecture-independent gadget search. In Proceedings of the USENIX Workshop on Offensive Technologies (WOOT). H. Shacham and C. Miller Eds., USENIX."},{"key":"e_1_2_2_18_1","first-page":"9","article-title":"Bypassing PaX ASLR protection","volume":"59","author":"Durden T.","year":"2002","unstructured":"Durden , T. 2002 . Bypassing PaX ASLR protection . Phrack Mag. 59 , 9 . http:\/\/www.phrack.org\/archives\/59\/p59_0x09_Bypassing&percnt;20PaX&percnt;20ASLR&percnt;20pro&percnt;tection_by_Tyler&percnt;20Durden.txt. Durden, T. 2002. Bypassing PaX ASLR protection. Phrack Mag. 59, 9. http:\/\/www.phrack.org\/archives\/59\/p59_0x09_Bypassing&percnt;20PaX&percnt;20ASLR&percnt;20pro&percnt;tection_by_Tyler&percnt;20Durden.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_19_1","volume-title":"Foundations of Security Analysis and Design IV","author":"Erlingsson U.","unstructured":"Erlingsson , U. 2007. Low-level software security: Attacks and defenses . In Foundations of Security Analysis and Design IV , A. Aldini and R. Gorrieri Eds., Lecture Notes in Computer Science, vol. 4677 . Springer-Verlag , 92--134. Erlingsson, U. 2007. Low-level software security: Attacks and defenses. In Foundations of Security Analysis and Design IV, A. Aldini and R. Gorrieri Eds., Lecture Notes in Computer Science, vol. 4677. Springer-Verlag, 92--134."},{"key":"e_1_2_2_20_1","volume-title":"Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI). B. Bershad and J. Mogul Eds., USENIX, 75--88","author":"Erlingsson U.","unstructured":"Erlingsson , U. , Abadi , M. , Vrable , M. , Budiu , M. , and Necula , G . 2006. XFI: Software guards for system address spaces . In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI). B. Bershad and J. Mogul Eds., USENIX, 75--88 . Erlingsson, U., Abadi, M., Vrable, M., Budiu, M., and Necula, G. 2006. XFI: Software guards for system address spaces. In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI). B. Bershad and J. Mogul Eds., USENIX, 75--88."},{"key":"e_1_2_2_21_1","first-page":"25","article-title":"ProPolice: Improved stack-smashing attack detection","volume":"14","author":"Etoh H.","year":"2001","unstructured":"Etoh , H. and Yoda , K. 2001 . ProPolice: Improved stack-smashing attack detection . IPSJ SIGNotes Comp. Sec. 14 , 25 . http:\/\/www.trl.ibm.com\/projects\/security\/ssp. Etoh, H. and Yoda, K. 2001. ProPolice: Improved stack-smashing attack detection. IPSJ SIGNotes Comp. Sec. 14, 25. http:\/\/www.trl.ibm.com\/projects\/security\/ssp.","journal-title":"IPSJ SIGNotes Comp. Sec."},{"key":"e_1_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455775"},{"key":"e_1_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655077.1655083"},{"key":"e_1_2_2_24_1","volume-title":"Proceedings of the USENIX Security Symposium. D. Wallach Ed., USENIX, 55--66","author":"Frantzen M.","unstructured":"Frantzen , M. and Shuey , M . 2001. StackGhost: Hardware facilitated stack protection . In Proceedings of the USENIX Security Symposium. D. Wallach Ed., USENIX, 55--66 . Frantzen, M. and Shuey, M. 2001. StackGhost: Hardware facilitated stack protection. In Proceedings of the USENIX Security Symposium. D. Wallach Ed., USENIX, 55--66."},{"key":"e_1_2_2_25_1","unstructured":"Garg M. 2006a. About ELF auxiliary vectors. http:\/\/manugarg.googlepages.com\/aboutelfauxiliaryvectors. Garg M. 2006a. About ELF auxiliary vectors. http:\/\/manugarg.googlepages.com\/aboutelfauxiliaryvectors."},{"key":"e_1_2_2_26_1","unstructured":"Garg M. 2006b. Sysenter-based system call mechanism in Linux 2.6. http:\/\/manugarg.googlepages.com\/systemcallinlinux2_6.html. Garg M. 2006b. Sysenter-based system call mechanism in Linux 2.6. http:\/\/manugarg.googlepages.com\/systemcallinlinux2_6.html."},{"key":"e_1_2_2_27_1","first-page":"7","article-title":"Advances in format string exploiting","volume":"59","year":"2001","unstructured":"gera and riq. 2001 . Advances in format string exploiting . Phrack Mag. 59 , 7 . http:\/\/www.phrack.org\/archives\/59\/p59_0x07_Advances&percnt;20in&percnt;20format&percnt;20string&percnt;20exploitation_by_riq&percnt;20&&percnt;&percnt;20gera.txt. gera and riq. 2001. Advances in format string exploiting. Phrack Mag. 59, 7. http:\/\/www.phrack.org\/archives\/59\/p59_0x07_Advances&percnt;20in&percnt;20format&percnt;20string&percnt;20exploitation_by_riq&percnt;20&&percnt;&percnt;20gera.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_28_1","unstructured":"Heelan S. 2010. Validity satisfiability and code semantics. http:\/\/seanhn.wordpress.com\/2010\/10\/02\/validity-satisfiability- and-instruction-semantics\/. Heelan S. 2010. Validity satisfiability and code semantics. http:\/\/seanhn.wordpress.com\/2010\/10\/02\/validity-satisfiability- and-instruction-semantics\/."},{"key":"e_1_2_2_29_1","first-page":"9","article-title":"Big loop integer protection","volume":"60","author":"Horovitz O.","year":"2002","unstructured":"Horovitz , O. 2002 . Big loop integer protection . Phrack Mag. 60 , 9 . http:\/\/www.phrack.org\/archives\/60\/p60_0x09_Big&percnt;20Loop&percnt;20Integer&percnt;20Protection_by_Oded&percnt;20Horovitz.txt. Horovitz, O. 2002. Big loop integer protection. Phrack Mag. 60, 9. http:\/\/www.phrack.org\/archives\/60\/p60_0x09_Big&percnt;20Loop&percnt;20Integer&percnt;20Protection_by_Oded&percnt;20Horovitz.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_30_1","volume-title":"Proceedings of the USENIX Security Symposium. F. Monrose Ed., USENIX, 383--398","author":"Hund R.","unstructured":"Hund , R. , Holz , T. , and Freiling , F . 2009. Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms . In Proceedings of the USENIX Security Symposium. F. Monrose Ed., USENIX, 383--398 . Hund, R., Holz, T., and Freiling, F. 2009. Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms. In Proceedings of the USENIX Security Symposium. F. Monrose Ed., USENIX, 383--398."},{"key":"e_1_2_2_31_1","volume-title":"Vols. 1--3B","author":"Intel Corporation","unstructured":"Intel Corporation . 2011. Intel 64 and IA-32 Architectures Software Developer\u2019s Manual , Vols. 1--3B . Intel Corporation . http:\/\/www.intel.com\/products\/processor\/manuals\/. Intel Corporation. 2011. Intel 64 and IA-32 Architectures Software Developer\u2019s Manual, Vols. 1--3B. Intel Corporation. http:\/\/www.intel.com\/products\/processor\/manuals\/."},{"key":"e_1_2_2_32_1","unstructured":"Iozzo V. and Miller C. 2009. Fun and games with Mac OS X and iPhone payloads. Black Hat Europe (Presentation slides). http:\/\/www.blackhat.com\/presentations\/bh-europe-09\/Miller_Iozzo\/BlackHat-Europe-2009-Miller-Iozzo-OSX-IPhone-Payloads-whitepaper.pdf. Iozzo V. and Miller C. 2009. Fun and games with Mac OS X and iPhone payloads. Black Hat Europe (Presentation slides). http:\/\/www.blackhat.com\/presentations\/bh-europe-09\/Miller_Iozzo\/BlackHat-Europe-2009-Miller-Iozzo-OSX-IPhone-Payloads-whitepaper.pdf."},{"key":"e_1_2_2_33_1","volume-title":"-P","author":"Iozzo V.","year":"2010","unstructured":"Iozzo , V. , Kornau , T. , and Weinmann , R . -P . 2010 . Everybody be cool this is a roppery! Black Hat . http:\/\/www.zynamics.com\/downloads\/bh10_paper.pdf. Iozzo, V., Kornau, T., and Weinmann, R.-P. 2010. Everybody be cool this is a roppery! Black Hat. http:\/\/www.zynamics.com\/downloads\/bh10_paper.pdf."},{"key":"e_1_2_2_34_1","volume-title":"Re: Older SPARC return-into-libc exploits. Penetration testing, SECLISTS. ORA.","author":"Ivaldi M.","year":"2007","unstructured":"Ivaldi , M. 2007 . Re: Older SPARC return-into-libc exploits. Penetration testing, SECLISTS. ORA. Ivaldi, M. 2007. Re: Older SPARC return-into-libc exploits. Penetration testing, SECLISTS. ORA."},{"key":"e_1_2_2_35_1","first-page":"8","article-title":"Vudo malloc tricks","volume":"57","author":"Kaempf M.","year":"2001","unstructured":"Kaempf , M. 2001 . Vudo malloc tricks . Phrack Mag. 57 , 8 . http:\/\/www.phrack.org\/archives\/57\/p57_0x08_Vudo&percnt;20malloc&percnt;20tricks_by_MaXX.txt. Kaempf, M. 2001. Vudo malloc tricks. Phrack Mag. 57, 8. http:\/\/www.phrack.org\/archives\/57\/p57_0x08_Vudo&percnt;20malloc&percnt;20tricks_by_MaXX.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_36_1","first-page":"8","article-title":"The frame pointer overwrite","volume":"55","year":"1999","unstructured":"klog. 1999 . The frame pointer overwrite . Phrack Mag. 55 , 8 . http:\/\/www.phrack.org\/archives\/55\/p55_0x08_Frame&percnt;20Pointer&percnt;20Overwriting_by_klog.txt. klog. 1999. The frame pointer overwrite. Phrack Mag. 55, 8. http:\/\/www.phrack.org\/archives\/55\/p55_0x08_Frame&percnt;20Pointer&percnt;20Overwriting_by_klog.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_38_1","unstructured":"Krahmer S. 2005. x86-64 buffer overflow exploits and the borrowed code chunks exploitation technique. http:\/\/www.suse.de\/~krahmer\/no-nx.pdf. Krahmer S. 2005. x86-64 buffer overflow exploits and the borrowed code chunks exploitation technique. http:\/\/www.suse.de\/~krahmer\/no-nx.pdf."},{"key":"e_1_2_2_39_1","unstructured":"Le L. 2010. Payload already inside: Data re-use for ROP exploits.  Black Hat. https:\/\/media.blackhat.com\/bh-us-10\/whitepapers\/Le\/BlackHat-USA-2010-Le-Paper-Payload-already-inside-data-reuse-for-ROP-exploits-wp.pdf. Le L. 2010. Payload already inside: Data re-use for ROP exploits. Black Hat . https:\/\/media.blackhat.com\/bh-us-10\/whitepapers\/Le\/BlackHat-USA-2010-Le-Paper-Payload-already-inside-data-reuse-for-ROP-exploits-wp.pdf."},{"key":"e_1_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755913.1755934"},{"key":"e_1_2_2_41_1","unstructured":"Lidner F. 2009. Developments in Cisco IOS forensics. CONFidence 2.0. (Presentation slides). http:\/\/www.recurity-labs.com\/content\/pub\/FX_Router_Exploitation.pdf. Lidner F. 2009. Developments in Cisco IOS forensics. CONFidence 2.0. (Presentation slides). http:\/\/www.recurity-labs.com\/content\/pub\/FX_Router_Exploitation.pdf."},{"key":"e_1_2_2_42_1","unstructured":"McDonald J. 1999. Defeating Solaris\/SPARC non-executable stack protection. Bugtraq. McDonald J. 1999. Defeating Solaris\/SPARC non-executable stack protection. Bugtraq."},{"key":"e_1_2_2_43_1","volume-title":"BlackHat Europe 2009 Conference. https:\/\/www.blackhat.com\/presentations\/bh-europe-09\/Miller_Iozzo\/ BlackHat-Europe-2009-Miller-Iozzo-OSX-IPhone-Payloads-whitepaper.pdf.","author":"Miller C.","unstructured":"Miller , C. and Iozzo , V . 2009. Fun and games with Mac OS X and iPhone payloads . Presented at the BlackHat Europe 2009 Conference. https:\/\/www.blackhat.com\/presentations\/bh-europe-09\/Miller_Iozzo\/ BlackHat-Europe-2009-Miller-Iozzo-OSX-IPhone-Payloads-whitepaper.pdf. Miller, C. and Iozzo, V. 2009. Fun and games with Mac OS X and iPhone payloads. Presented at the BlackHat Europe 2009 Conference. https:\/\/www.blackhat.com\/presentations\/bh-europe-09\/Miller_Iozzo\/ BlackHat-Europe-2009-Miller-Iozzo-OSX-IPhone-Payloads-whitepaper.pdf."},{"key":"e_1_2_2_44_1","unstructured":"Naraine R. 2010. Pwn2Own 2010: iPhone hacked SMS database hijacked. http:\/\/blogs.zdnet.com\/security\/?p=5836. Naraine R. 2010. Pwn2Own 2010: iPhone hacked SMS database hijacked. http:\/\/blogs.zdnet.com\/security\/?p=5836."},{"key":"e_1_2_2_45_1","first-page":"4","article-title":"The advanced return-into-lib(c) exploits: PaX case study","volume":"58","author":"Nergal","year":"2001","unstructured":"Nergal . 2001 . The advanced return-into-lib(c) exploits: PaX case study . Phrack Mag. 58 , 4 . http:\/\/www.phrack.org\/archives\/58\/p58_0x04_Advanced&percnt;20return-into-lib(c)&percnt;20exploits&percnt;20(PaX&percnt;20case&percnt;20study)_by_nergal.txt. Nergal. 2001. The advanced return-into-lib(c) exploits: PaX case study. Phrack Mag. 58, 4. http:\/\/www.phrack.org\/archives\/58\/p58_0x04_Advanced&percnt;20return-into-lib(c)&percnt;20exploits&percnt;20(PaX&percnt;20case&percnt;20study)_by_nergal.txt.","journal-title":"Phrack Mag."},{"key":"e_1_2_2_46_1","volume-title":"Re: Smashing the stack: Prevention? Bugtraq","author":"Newsham T.","year":"1997","unstructured":"Newsham , T. 1997 . Re: Smashing the stack: Prevention? Bugtraq . http:\/\/seclists.org\/bugtraq\/1997\/Apr\/129. Newsham, T. 1997. Re: Smashing the stack: Prevention? Bugtraq. http:\/\/seclists.org\/bugtraq\/1997\/Apr\/129."},{"key":"e_1_2_2_47_1","unstructured":"Newsham T. 2000. Non-exec stack. Bugtraq. http:\/\/seclists.org\/bugtraq\/2000\/May\/90. Newsham T. 2000. Non-exec stack. Bugtraq. http:\/\/seclists.org\/bugtraq\/2000\/May\/90."},{"key":"e_1_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920269"},{"key":"e_1_2_2_49_1","volume-title":"Assembly Language Programming, and C","author":"Paul R. P.","unstructured":"Paul , R. P. 1999. SPARC Architecture , Assembly Language Programming, and C . Prentice Hall PTR , Upper Saddle River, NJ. Paul, R. P. 1999. SPARC Architecture, Assembly Language Programming, and C. Prentice Hall PTR, Upper Saddle River, NJ."},{"key":"e_1_2_2_50_1","unstructured":"PaX Team. 2003a. PaX address space layout randomization. http:\/\/pax.grsecurity.net\/docs\/aslr.txt. PaX Team . 2003a. PaX address space layout randomization. http:\/\/pax.grsecurity.net\/docs\/aslr.txt."},{"key":"e_1_2_2_51_1","unstructured":"PaX Team. 2003b. PaX non-executable pages design & implementation. http:\/\/pax.grsecurity.net\/docs\/noexec.txt. PaX Team . 2003b. PaX non-executable pages design & implementation. http:\/\/pax.grsecurity.net\/docs\/noexec.txt."},{"key":"e_1_2_2_52_1","volume-title":"SEGMEXEC: Segmentation based non-executable pages","author":"Pa X","year":"2003","unstructured":"Pa X Team . 2003 c. SEGMEXEC: Segmentation based non-executable pages . http:\/\/pax.grsecurity.net\/docs\/segmexec.txt. PaX Team. 2003c. SEGMEXEC: Segmentation based non-executable pages. http:\/\/pax.grsecurity.net\/docs\/segmexec.txt."},{"key":"e_1_2_2_53_1","volume-title":"Re: Future of buffer overflows? Bugtraq","author":"Richarte G.","year":"2000","unstructured":"Richarte , G. 2000 . Re: Future of buffer overflows? Bugtraq . http:\/\/seclists.org\/bugtraq\/2000\/Nov\/32 and http:\/\/seclists.org\/bugtraq\/2000\/Nov\/26. Richarte, G. 2000. Re: Future of buffer overflows? Bugtraq. http:\/\/seclists.org\/bugtraq\/2000\/Nov\/32 and http:\/\/seclists.org\/bugtraq\/2000\/Nov\/26."},{"key":"e_1_2_2_54_1","unstructured":"Richarte G. 2001. Insecure programming by example: Esoteric #2. http:\/\/community.corest.com\/~gera\/InsecureProgramming\/e2.html. Richarte G. 2001. Insecure programming by example: Esoteric #2. http:\/\/community.corest.com\/~gera\/InsecureProgramming\/e2.html."},{"key":"e_1_2_2_56_1","volume-title":"System V Application Binary Interface: Intel386 Architecture Processor Supplement","author":"Santa Cruz Operation","unstructured":"Santa Cruz Operation 1996. System V Application Binary Interface: Intel386 Architecture Processor Supplement 4 th Ed., The Santa Cruz Operation . Santa Cruz Operation 1996. System V Application Binary Interface: Intel386 Architecture Processor Supplement 4th Ed., The Santa Cruz Operation.","edition":"4"},{"key":"e_1_2_2_57_1","volume-title":"Proceedings of the USENIX Security Symposium, D. Wagner Ed., USENIX.","author":"Schwartz E.","unstructured":"Schwartz , E. , Avgerinos , T. , and Brumley , D . 2011. Q: Exploit hardening made easy . In Proceedings of the USENIX Security Symposium, D. Wagner Ed., USENIX. Schwartz, E., Avgerinos, T., and Brumley, D. 2011. Q: Exploit hardening made easy. In Proceedings of the USENIX Security Symposium, D. Wagner Ed., USENIX."},{"key":"e_1_2_2_58_1","unstructured":"Scut\/team teso. 2001. Exploiting format string vulnerabilities. http:\/\/www.team-teso.net. Scut\/team teso . 2001. Exploiting format string vulnerabilities. http:\/\/www.team-teso.net."},{"key":"e_1_2_2_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_2_2_61_1","unstructured":"Solar Designer. 1997. Getting around non-executable stack (and fix). Bugtraq moving hot. Solar Designer . 1997. Getting around non-executable stack (and fix). Bugtraq moving hot."},{"key":"e_1_2_2_62_1","unstructured":"Solar Designer. 1998. StackPatch. http:\/\/www.openwall.com\/linux. Solar Designer . 1998. StackPatch. http:\/\/www.openwall.com\/linux."},{"key":"e_1_2_2_63_1","unstructured":"Solar Designer. 2000. JPEG COM marker processing vulnerability in Netscape browsers. http:\/\/www.openwall.com\/advisories\/OW-002-netscape-jpeg\/. Solar Designer . 2000. JPEG COM marker processing vulnerability in Netscape browsers. http:\/\/www.openwall.com\/advisories\/OW-002-netscape-jpeg\/."},{"key":"e_1_2_2_64_1","volume-title":"SPARC  Processor Supplement","author":"SPARC Int. Inc. 1996.","unstructured":"SPARC Int. Inc. 1996. System V Application Binary Interface , SPARC Processor Supplement . SPARC Inc . SPARC Int. Inc. 1996. System V Application Binary Interface, SPARC Processor Supplement. SPARC Inc."},{"key":"e_1_2_2_65_1","article-title":"The SPARC Architecture Manual Version 9. SPARC","author":"Weaver D.","year":"1994","unstructured":"Weaver , D. and Germond , T. , Eds. 1994 . The SPARC Architecture Manual Version 9. SPARC Int. Inc., Englewood Cliffs, NJ. Weaver, D. and Germond, T., Eds. 1994. The SPARC Architecture Manual Version 9. SPARC Int. Inc., Englewood Cliffs, NJ.","journal-title":"Int. Inc., Englewood Cliffs, NJ."},{"key":"e_1_2_2_66_1","unstructured":"Zalewski M. 2001. Remote vulnerability in SSH daemon CRC32 compression attack detector. http:\/\/www.bindview.com\/Support\/RAZOR\/Advisories\/2001\/adv_ssh1crc.cfm. Zalewski M. 2001. Remote vulnerability in SSH daemon CRC32 compression attack detector. http:\/\/www.bindview.com\/Support\/RAZOR\/Advisories\/2001\/adv_ssh1crc.cfm."}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2133375.2133377","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2133375.2133377","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:06:05Z","timestamp":1750241165000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2133375.2133377"}},"subtitle":["Systems, Languages, and Applications"],"short-title":[],"issued":{"date-parts":[[2012,3]]},"references-count":64,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2012,3]]}},"alternative-id":["10.1145\/2133375.2133377"],"URL":"https:\/\/doi.org\/10.1145\/2133375.2133377","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,3]]},"assertion":[{"value":"2009-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-06-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-03-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}