22.09.2016 Views

JIT Spraying Never Dies

JIT%20Spraying%20Never%20Dies%20-%20Bypass%20CFG%20By%20Leveraging%20WARP%20Shader%20JIT%20Spraying

JIT%20Spraying%20Never%20Dies%20-%20Bypass%20CFG%20By%20Leveraging%20WARP%20Shader%20JIT%20Spraying

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Possibility of Exploiting<br />

64-bit Browser<br />

* <strong>Spraying</strong> 9G is big enough to make some address covered, but it still<br />

needs some searching to find the <strong>JIT</strong> gadget within each 1/2G section.<br />

Data<br />

Code<br />

* In fact no need to spray such a huge space if AAR is acquired, the<br />

Check this option to add<br />

<strong>JIT</strong> page address can be deduced by leaking WARP module base.<br />

support for D3D10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!