video thumbnail 13:31
WebKit RegExp Exploit addrof() walk-through

2019-06-16

[public] 34.8K views, 1.33K likes, 11.0 dislikes audio only

channel thumbLiveOverflow

Part 4: We finally look at the actual exploit code. We start by understanding the addrof() primitive used to leak the address of a JavaScript object in memory.

test.js: https://gist.github.com/LiveOverflow/ee5fb772334ec985094f77c91be60492

Crash investigation: https://webkit.org/blog/6411/javascriptcore-csi-a-crash-site-investigation-story/

The Exploit: https://github.com/LinusHenze/WebKit-RegEx-Exploit

The Fix: https://github.com/WebKit/webkit/commit/7cf9d2911af9f255e0301ea16604c9fa4af340e2?diff=split#diff-fb5fbac6e9d7542468cfeed930e241c0L66

Saelo's exploit: https://github.com/saelo/cve-2018-4233/blob/master/pwn.js

Playlist: /youtube/video/5tEdSoZ3mmE

-=[ πŸ•΄οΈAdvertisement ]=-

This video is supported by SSD Secure Disclosure: https://ssd-disclosure.com/

Offensive Security Conference TyphoonCon: https://typhooncon.com/

-=[ ❀️ Support ]=-

β†’ per Video: https://www.patreon.com/join/liveoverflow

β†’ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ πŸ”΄ Stuff I use ]=-

β†’ Microphone:* https://geni.us/ntg3b

β†’ Graphics tablet:* https://geni.us/wacom-intuos

β†’ Camera#1 for streaming:* https://geni.us/sony-camera

β†’ Lens for streaming:* https://geni.us/sony-lense

β†’ Connect Camera#1 to PC:* https://geni.us/cam-link

β†’ Keyboard:* https://geni.us/mech-keyboard

β†’ Old Microphone:* https://geni.us/mic-at2020usb

US Store Front:* https://www.amazon.com/shop/liveoverflow

-=[ πŸ• Social ]=-

β†’ Twitter: https://twitter.com/LiveOverflow/

β†’ Website: https://liveoverflow.com/

β†’ Subreddit: https://www.reddit.com/r/LiveOverflow/

β†’ Facebook: https://www.facebook.com/LiveOverflow/

-=[ πŸ“„ P.S. ]=-

All links with "*" are affiliate links.

LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#browserexploitation


LiveOverflow just a wannabe hacker... making videos about various IT security topics and participating in hacking competitions. -=[ ❀️ Support me ]=- Patreon per Video: https://www.patreon.com/join/liveoverflow YouTube Membership per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ πŸ“„ Imprint ]=- Security Flag GmbH Celsiusstr. 72 12207 Berlin Germany
/youtube/channel/UClcE-kVhqyiHCcjYwcpfj9w
I’m moving, no videos sorry 17,541 views
/youtube/video/9CS3q0uG1LI
Patreon patreon.com
https://www.patreon.com/join/liveoverflow
Browser Exploitation by LiveOverflow
/youtube/video/5tEdSoZ3mmE