You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It's seems that pointer mangling protection in 2.32 work the same as CONFIG_SLAB_FREELIST_HARDENED=y
I think, it will be very very nice to read some material about techniques to deal with that type of exp from you, guys.
Thanks.
It'd be nice to see some write-ups on SLUB / SLAB exploitation.
It should be relatively easy to rip out the allocator and turn it into a user-space library a la
LD_PRELOAD
.The text was updated successfully, but these errors were encountered: