
Terminé un exploit fonctionnel pour CVE-2018-17463 pour le fun.
Exploit fonctionnel complété pour CVE-2018-17463 pour le plaisir.
L'article original que j'ai trouvé sur ce bug était ici http://phrack.org/papers/jit_exploitation.html. Je voulais juste vraiment transformer cette lecture/écriture arbitraire en un exploit entièrement fonctionnel.
J'ai aussi appris la technique JIT spray à partir de l'article suivant qui est une lecture intéressante.
@inproceedings{gawlik2018sok,
title={Sok: Make jit-spray great again},
author={Gawlik, Robert and Holz, Thorsten},
booktitle={12th $\{$USENIX$\}$ Workshop on Offensive Technologies ($\{$WOOT$\}$ 18)},
year={2018}
}
url: https://www.usenix.org/system/files/conference/woot18/woot18-paper-gawlik.pdf