Главная
Study mode:
on
1
Intro
2
On the Menu tonight
3
The SIGSEGV handler
4
Root cause analysis
5
What happened?
6
Refined PoC (easy)
7
Paper Plan
8
Generalization
9
Systematization
10
Does this actually affect real software
11
Finding a real-world vulnerability
12
Building the first exploit
13
The Reviews (excerpt/paraphrased)
14
Disclosure
15
Responses
16
Questions? Answers!
Description:
Explore the intricacies of exception handling and buffer overflows in this 46-minute conference talk from nullcon. Delve into a year-long investigation of exploit primitives, their presence in real-world software, and the development of new exploits for existing vulnerabilities. Follow the speakers' journey as they uncover a novel exploitation technique while examining the path of exceptions from throw to catch handler. Gain insights into the SIGSEGV handler, root cause analysis, and the process of refining proof-of-concepts. Learn about the systematic approach to generalizing findings and their real-world implications. Discover how the speakers identified vulnerabilities in actual software and constructed exploits. Understand the disclosure process and responses received. Conclude with a Q&A session to address audience inquiries and further discuss the presented concepts.

Chop Suey - An Exceptional Dish With A Side Of Buffer Overflows

nullcon
Add to list