What is the key technique to find Type Confusion bugs in browsers?
-
-
-
luck, persistence, and (most importantly) "data coverage": trying to feed semi- or invalid data to APIs and see if they bork.
-
What do you use for data coverage? And by data coverage, do you mean code coverage?
-
No: the same code will run fine with valid types of data & crash with invalid: you need to try every type of data you can find.
-
unfortunately I have no tools to check or force this: I attempt to exhaustively try every combination of data type + API
-
...which is where luck and persistence comes in :)
-
;-) Yeah
End of conversation
New conversation -
-
-
Hi, I remembered you meet with crashes which triggers INT3, how MS said those cases?
-
most of these are in Abandonment, which reports assertion failures, so not security vulnerabilities. BugId will tell you ;)
End of conversation
New conversation -
-
-
nice bug
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.