Twitter | Pretraživanje | |
Saar Amar
Let's take it further - isn't this type confusion can be used also on return addr for ROPs? We can ret to incorrect addrs (which are PAC signed). Ret addr uses current SP as context/tweak, so we are limited to addrs in the same depth ;) (, , , )
Reply Retweet Označi sa "sviđa mi se" More
qwertyoruiop 30. pro
Odgovor korisniku/ci @AmarSaar @s1guza i 2 ostali
this is called the “Qualcomm attack”, and was described in the pac white paper iirc
Reply Retweet Označi sa "sviđa mi se"
Saar Amar 30. pro
Odgovor korisniku/ci @qwertyoruiopz @s1guza i 2 ostali
Thx! didn't know that. Yeah, I see it now. Ref for others:
Reply Retweet Označi sa "sviđa mi se"