| Why ISE | Security Evaluation | System Design | Litigation Consulting | Publications | Contact | News |
Events |
Featured News |
|---|---|
Engineering Heap Overflows with JavaScriptJuly 28, 2008Jake Honoroff, Mark Daniel, Charlie Miller, presented at USENIX Workshop on Offensive Technologies (WOOT) 2008AbstractThis paper presents a new technique for exploiting heap over?ows in JavaScript interpreters. Brie?y, given a heap over?ow, JavaScript commands can be used to insure that a function pointer is reliably present for smashing, just after the over?own buffer. A case study serves to highlight the technique: the Safari exploit that the authors used to win the 2008 CanSecWest Pwn2Own contest.Slides |
Featured Publications2007
The Legitimate Vulnerability Market: The Secretive World of 0-day Exploit Sales. |