3 ms·
I'm a beginner when it comes to software development (mostly web development), but it seems to me that the majority of complex exploits like this involve some t
by SanPilot 10y ago
I'm a beginner when it comes to software development (mostly web development), but it seems to me that the majority of complex exploits like this involve some type of memory overflow and subsequent code execution.
Shouldn't there be methods for detecting these kinds of things in source code or more priority given to preventing it in the C/low-level community?
- startling 10y agoThere are. "(Kernel) address space layout randomization" is one of them. It was circumvented here; that's part of why this is impressive.
- SanPilot 10y agoHow is it possible to put the malicious code in the correct memory spaces? Unless the attacker had a full image of the memory, I don't see how this can be accomplished.
- startling 10y agoThe second bit of the exploit chain, CVE-2016-4655, leads to disclosure of kernel memory addresses. Once a single memory address is known, you can calculate the random offset of the kernel, and then exploit the third part to overwrite the return address and return into specific chunks of kernel code ("Return Oriented Programming"), whose addresses you computed from the offset + a fixed code location. These can let you e.g. install your payload.