Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kmfpl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
kmfpl
2y ago
Compiler can sometimes inline syscall wrappers, so not that easy to check statically. For the same reason searching for SVC instructions would yield tons of results. If you search for the exact syscall ID moved into X16 you’d find it immedi
2.
▲
by
kmfpl
2y ago
You also removed the giant pole stuck up your ass?
3.
▲
by
kmfpl
3y ago
I agree, this looks extremely sketchy. Especially because the code is just writing a fully controlled byte in the buffer and incrementing its index. This would give you a controlled relative write primitive if you can repeatedly call this f
4.
▲
Operation Triangulation attackers didn't have access to Apple leaks
(social.treehouse.systems)
2 points
by
kmfpl
3y ago
|
0 comments
5.
▲
What if we had the SockPuppet vulnerability in iOS 16?
(security.apple.com)
5 points
by
kmfpl
3y ago
|
0 comments
6.
▲
by
kmfpl
4y ago
Well, that’s 7 years of major updates with all the security fixes. Moreover, Apple continues to release minor versions for devices that are not supported anymore, in order to fix major flaws that are actively exploited ITW (see iOS from 12.
7.
▲
by
kmfpl
4y ago
This is simply how Apple does things. They provide software support for ~10 years and then they drop it. Is it wrong? I’m not entirely sure. You can call that greedy, but take a few things into consideration. Firstly, Apple provides highly
8.
▲
by
kmfpl
5y ago
With lldb you can do that, basically you have the option of running commands when a given breakpoint is hit, so you can just make it place another breakpoint, and it will be placed only if the first breakpoint is hit. I assume you can do so
9.
▲
by
kmfpl
5y ago
People in this thread seem very confused about a lot of stuff so I’m going to try and make some clarifications: 1) This is an RCE, so what it does is achieving code execution in the browser, i.e. it can run arbitrary code from the attacker,
10.
▲
by
kmfpl
5y ago
You understand that having W^X protections on any JIT area is fairly useless without a strong CFI model in place right? Any attacker could easily execute a ROP/JOP chain to switch JIT protections to RX or even more simply allocate an R
11.
▲
by
kmfpl
6y ago
Normally bugs in these types of attacks target daemons that are always connected even if not logged onto iMessage or even if you disable iMessage. Or at least this was the case with previously known bugs.
12.
▲
by
kmfpl
6y ago
>“Just reboot your phone, and you're good to go” Doesn’t really work like that. First of all, when would you reboot your phone? Once per day? Once per hour? Every five minutes? Regardless, these attacks are incredibly advanced, reme