SlideShare une entreprise Scribd logo
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
bu jscript9!Js::ScriptContext::IsInEvalMap
".echo EVAL(dyn)-----;.printf "%mu", poi(esp+0x18);.echo;g"
•
•
•
•
•
•
•
.foreach /s (exc "ct et cpr ld ud ser ibp iml asrt aph eh clr clrn dm ip dz iov
ch hc lsq isc 3c svh sse ssec vs vcpp wkd rto rtt wos *") {sxi ${exc}}
.foreach /s (exc "epr sbo sov gp ii av") {sxe ${exc}}
•
•
•
• FITZL.CSABA@GMAIL.COM
•
•
• SZIMEUS@GMAIL.COM

Contenu connexe

Plus de Csaba Fitzl (6)

Exploiting XPC in AntiVirus
Exploiting XPC in AntiVirusExploiting XPC in AntiVirus
Exploiting XPC in AntiVirus
 
GateKeeper - bypass or not bypass?
GateKeeper - bypass or not bypass?GateKeeper - bypass or not bypass?
GateKeeper - bypass or not bypass?
 
Getting root with benign app store apps vsecurityfest
Getting root with benign app store apps vsecurityfestGetting root with benign app store apps vsecurityfest
Getting root with benign app store apps vsecurityfest
 
Getting root with benign app store apps
Getting root with benign app store appsGetting root with benign app store apps
Getting root with benign app store apps
 
Exploit generation automation with WinDBG (Hacktivity 2017)
Exploit generation automation with WinDBG (Hacktivity 2017)Exploit generation automation with WinDBG (Hacktivity 2017)
Exploit generation automation with WinDBG (Hacktivity 2017)
 
How to convince a malware to avoid us
How to convince a malware to avoid usHow to convince a malware to avoid us
How to convince a malware to avoid us
 

Exploit generation and javascript analysis automation with WinDBG lu