王楠与肖正航与郭学浩与戴秦润_超级帽子戏法四次利用Chrome和Firefox_WP.pdf

编号:175544 PDF 30页 915.34KB 下载积分:VIP专享
下载报告请您先登录!

王楠与肖正航与郭学浩与戴秦润_超级帽子戏法四次利用Chrome和Firefox_WP.pdf

1、White Paper(Super Hat Trick:Exploit Chrome and Firefox Four Times)1White Paper(Super Hat Trick:Exploit Chrome and Firefox Four Times)BackgroundWith the widespread use of the JavaScript language,JavaScript engines are becoming increasingly feature-rich.There are various JavaScript engines,such as V8

2、used by Google Chrome and SpiderMonkey used by Firefox.From runtime support to compilation optimization,they add a lot of new code,but with it comes a bunch of hidden security issues.We have once again identified four high-risk vulnerabilities in these new implementations:one is related to a classic

3、 callback issue within the new runtime support implementations,another is related to type confusion caused by missing type checking in the compilation optimization,and BackgroundCallback issue in runtime supportBackgroundRoot cause analysisHow to exploitIncorrect Assumption on JS MapBackgroundRoot c

4、ause analysisHow to exploitInitialization Flaw in WebAssembly InstancesBackgroundRoot cause analysisHow to exploitInteger Overflow in WebAssembly JITBackgroundRoot cause analysisHow to exploitConclusionsWhite Paper(Super Hat Trick:Exploit Chrome and Firefox Four Times)2the remaining two are related

5、to wasm gc issuesimproper initialization order and integer overflow,resulting in controllable out-of-bounds read/write.Callback issue in runtime supportBackgroundThe first part is a callback issue,which is hidden in the runtime support code logic,and is related to a new Javascript proposal.Before di

6、ve deeper into the root causes of vulnerability,lets first have a brief understanding of the background knowledge.In 2015,a new data structure Set,was introduced into the Javascript,to make the developer more easier to code.However,as you can see,the functions available in this Set structure are ver

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(王楠与肖正航与郭学浩与戴秦润_超级帽子戏法四次利用Chrome和Firefox_WP.pdf)为本站 (张5G) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠