There's a bunch of misinformation about the new Firefox exploit so I'd like to clear a few things up. https://twitter.com/movrcx/status/803744059022069760 …
-
This Tweet is unavailable.
-
Replying to @dguido
Thanks to the efforts from a few dedicated members of Trail of Bits (
@withzombies, scott, and others), I have real info to share.1 reply 7 retweets 13 likes -
Replying to @dguido
First off, it's a garden variety use-after-free, not a heap overflow, and it affects the SVG parser Firefox.
3 replies 11 retweets 19 likes -
Replying to @dguido
MWR published research in this area years ago in WebKit, and it appears that Firefox is lagging a few years behind. https://labs.mwrinfosecurity.com/blog/mwr-labs-pwn2own-2013-write-up-webkit-exploit/ …
1 reply 16 retweets 28 likes -
Replying to @dguido
As far as exploit techniques, this is a routine UAF that heap sprays a controlled object to kick off a ROP chain. Pwn2Own 2012-level tech.
1 reply 20 retweets 26 likes -
Replying to @dguido
The controlled object eventually gives them RW access to memory, then its game over.
1 reply 2 retweets 4 likes -
Replying to @dguido
This is not an advanced exploit. If you want to see one of those, check out Pegasus which had to deal with code signing and JIT pages.
2 replies 11 retweets 19 likes -
Replying to @dguido
This type of exploit is much harder to write in Chrome and Edge due to memory partitioning, an exploit mitigation that Firefox lacks.
1 reply 13 retweets 14 likes -
Replying to @dguido
If you thought this exploit was from MSF, it's not. MSF has 8 Firefox exploits, none of them match this new one.
4 replies 3 retweets 2 likes
The version regex in the exploit matches Firefox 49, and the specific user-agent that the Tor Browser Bundle uses.pic.twitter.com/OjMf6T4JHA
-
-
Replying to @dguido
The vulnerability is present on macOS, but the exploit does not include support for targeting any operating system but Windows.
1 reply 8 retweets 6 likes -
Replying to @dguido
If you were wondering, Mozilla is aware of the bug and has an open issue to track it.http://hg.mozilla.org/mozilla-central/rev/adcc39e3cad0 …
2 replies 9 retweets 6 likes - 6 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.