WebKit RegExp Exploit Addrof() Walk-Through

IjyDsVOIx8Y/default.jpg

Part 4: We finally look at the actual exploit code. We start by understanding the addrof() primitive used to leak the address of a JavaScript object in memory.

test.js: https://gist.github.com/LiveOverflow/...
Crash investigation: https://webkit.org/blog/6411/javascri...
The Exploit: https://github.com/LinusHenze/WebKit-...
The Fix: https://github.com/WebKit/webkit/comm...
Saelo's exploit: https://github.com/saelo/cve-2018-423...

Playlist: https://www.youtube.com/watch?v=5tEdS...

-=[ 🕴️Advertisement ]=-

This video is supported by SSD Secure Disclosure: https://ssd-disclosure.com/
Offensive Security Conference TyphoonCon: https://typhooncon.com/

-=[ ❤️ Support ]=-

→ per Video: https://www.patreon.com/join/liveover...
→ per Month: https://www.youtube.com/channel/UClcE...

-=[ 🔴 Stuff I use ]=-

→ Microphone:* https://amzn.to/2LW6ldx
→ Graphics tablet:* https://amzn.to/2C8djYj
→ Camera#1 for streaming:* https://amzn.to/2SJ66VM
→ Lens for streaming:* https://amzn.to/2CdG31I
→ Connect Camera#1 to PC:* https://amzn.to/2VDRhWj
→ Camera#2 for electronics:* https://amzn.to/2LWxehv
→ Lens for macro shots:* https://amzn.to/2C5tXrw
→ Keyboard:* https://amzn.to/2LZgCFD
→ Headphones:* https://amzn.to/2M2KhxW

-=[ 🐕 Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/
→ Website: https://liveoverflow.com/
→ Subreddit: https://www.reddit.com/r/LiveOverflow/
→ Facebook: https://www.facebook.com/LiveOverflow/

-=[ 📄 P.S. ]=-

All links with "*" are affiliate links.
LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#browserexploitation

IjyDsVOIx8Y/default.jpg
WebKit RegExp Exploit Addrof() Walk-Through WebKit RegExp Exploit Addrof() Walk-Through Reviewed by Anonymous on June 16, 2019 Rating: 5