@LiveOverflow
  @LiveOverflow
LiveOverflow | WebKit RegExp Exploit addrof() walk-through @LiveOverflow | Uploaded 5 years ago | Updated 7 hours ago
Part 4: We finally look at the actual exploit code. We start by understanding the addrof() primitive used to leak the address of a JavaScript object in memory.

test.js: gist.github.com/LiveOverflow/ee5fb772334ec985094f77c91be60492
Crash investigation: webkit.org/blog/6411/javascriptcore-csi-a-crash-site-investigation-story
The Exploit: github.com/LinusHenze/WebKit-RegEx-Exploit
The Fix: github.com/WebKit/webkit/commit/7cf9d2911af9f255e0301ea16604c9fa4af340e2?diff=split#diff-fb5fbac6e9d7542468cfeed930e241c0L66
Saelo's exploit: github.com/saelo/cve-2018-4233/blob/master/pwn.js

Playlist: youtube.com/watch?v=5tEdSoZ3mmE&list=PLhixgUqwRTjwufDsT1ntgOY9yjZgg5H_t

-=[ πŸ•΄οΈAdvertisement ]=-

This video is supported by SSD Secure Disclosure: ssd-disclosure.com
Offensive Security Conference TyphoonCon: typhooncon.com

-=[ ❀️ Support ]=-

β†’ per Video: patreon.com/join/liveoverflow
β†’ per Month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ πŸ”΄ Stuff I use ]=-

β†’ Microphone:* geni.us/ntg3b
β†’ Graphics tablet:* geni.us/wacom-intuos
β†’ Camera#1 for streaming:* geni.us/sony-camera
β†’ Lens for streaming:* geni.us/sony-lense
β†’ Connect Camera#1 to PC:* geni.us/cam-link
β†’ Keyboard:* geni.us/mech-keyboard
β†’ Old Microphone:* geni.us/mic-at2020usb

US Store Front:* amazon.com/shop/liveoverflow

-=[ πŸ• Social ]=-

β†’ Twitter: twitter.com/LiveOverflow
β†’ Website: liveoverflow.com
β†’ Subreddit: reddit.com/r/LiveOverflow
β†’ Facebook: facebook.com/LiveOverflow

-=[ πŸ“„ P.S. ]=-

All links with "*" are affiliate links.
LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#browserexploitation
WebKit RegExp Exploit addrof() walk-through$100k Hacking Prize - Security Bugs in Google Cloud Platformey! Look for patternsDO NOT USE alert(1) for XSSThe Butterfly of JSObjectGuessing vs. Not Knowing in Hacking and CTFsCTFs are AWESOME!YouTube BANNING Hacking Videos - Hot TakeI made every video I ever wanted to makeHow To Learn Something New? - Game Devlog #1How To Learn Hacking With CTFsReinventing Web Security

WebKit RegExp Exploit addrof() walk-through @LiveOverflow

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER