I don't quite get how that jump into any OCM location gives me code exec. How do I get my payload to jump to into OCM? How do I set up a stack to do ROP using gadgets from the FSBL? How do I find gadgets if I only have the AES-GCM encrypted FSBL? Am I missing something?
-
-
-
You get to jump to the *decrypted* FSBL in memory.
- Još 3 druga odgovora
Novi razgovor -
-
-
That's one of the reason why we don't trust any ready made commercial CPU and we prefer to run everything inside our FPGA. We run any code only from inside our embedded flash. Good catch !!!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.