One of my hobbies is to read and annotate interesting public exploits. This gives a good opportunity to force myself into studying code/material that I'm not familiar with, and be able to catch up with recent exploitation techniques that cope with current mitigations.
-
-
This probably has a few consequences, not least that the region of ports within which it searches for the corruption is likely shifted so the corruption might succeed but it'll keep going, eventually panicking.
-
struct ipc_kmsg is a header for a variable sized structure; I explain it here: https://googleprojectzero.blogspot.com/2017/04/exception-oriented-exploitation-on-ios.html … that's why it looks like I'm reading off the end of it; the mach message body is actually aligned to the end of the allocation.
- 2 more replies
New conversation -
-
-
I’ll take a closer look tonight on some 16k page devices; maybe they don’t actually take 16k per port zcram. Will post the results and some example code showing how you can find out.
-
I love watching you guys work
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
