Conversation

This Tweet was deleted by the Tweet author. Learn more
This Tweet was deleted by the Tweet author. Learn more
a single ret won't work (reliably) for spoofing because the caller allocated stack space could be trashed, and that's where your proposed solution would place the return address anyways, to filter out everything reliably they'd need some sort of symbolic execution.