4 ms·
Zooming in on Zero-Click Exploits
- saagarjha 5y ago> ASLR is arguably the most important mitigation in preventing exploitation of memory corruption, and most other mitigations rely on it on some level to be effective. Hmm, not entirely sure I would agree. ASLR can help, sure, but ASLR isn't really that great in the context of other bugs (I guess this could be reworded as "it costs you one extra bug"). That said, Zoom should absolutely be using it, since it's so cheap.
- xony 5y ago
- zibzab 5y agoZoom has always been bad on security (& privacy). That's why prefer to use it in the browser when I really have to. Unfortunately they (and Teams) are making this harder and harder.
- egberts1 5y agoI think it is because Zoom uses Microsoft C# compiler (that .NET uses as well). This compiler makes execute and write to same memory segment possible, no? I did learn that backends of Zoom are made up of PHP, JavaScript (both server-sid and client-side), Python, CSS, and HTML.
- egberts1 5y agoTo prevent JIT Spraying, simply avoid EXecute-Write programs/applicatioms: - Just-In-Time Compiler - - JavaScript, in certain mode - - .NET (Microsoft C# compiler) - - Java Virtual Machine (JVM) - - Adobe ActionScript (embedded JavaScript) - Berkeley Packet Filter (Linux) API - Adobe Actionscript (Adobe Flash) As a security architect, you should be extremely mindful of the immense baggage that JIT design comes with. References - https://en.wikipedia.org/wiki/JIT_spraying https://en.wikipedia.org/wiki/JIT_spraying - https://en.wikipedia.org/wiki/W%5EX https://en.wikipedia.org/wiki/W%5EX