04.11.2014 Views

ROPs_are_for_the_99_CanSecWest_2014

ROPs_are_for_the_99_CanSecWest_2014

ROPs_are_for_the_99_CanSecWest_2014

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

About JScript 9<br />

I don’t have enough time to fully talk about <strong>the</strong><br />

internals of JScript 9 today, but I can tell you:<br />

JScript 9 is more exploit-friendly.<br />

Custom heaps, no gaps, less random<br />

More raw internal data structures<br />

More “interesting” objects<br />

…<br />

Although JScript 9 no longer use BSTR to store<br />

String object data, but <strong>the</strong>re is some o<strong>the</strong>r new<br />

data structures like BSTR.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!