22.09.2016 Views

JIT Spraying Never Dies

JIT%20Spraying%20Never%20Dies%20-%20Bypass%20CFG%20By%20Leveraging%20WARP%20Shader%20JIT%20Spraying

JIT%20Spraying%20Never%20Dies%20-%20Bypass%20CFG%20By%20Leveraging%20WARP%20Shader%20JIT%20Spraying

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

References<br />

• https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Bypass-<br />

Control-Flow-Guard-Comprehensively-wp.pdf<br />

• http://xlab.tencent.com/en/2015/12/09/bypass-dep-and-cfg-using-jitcompiler-in-charkra-engine/<br />

• http://xlab.tencent.com/en/2016/01/04/use-chakra-engine-again-to-bypasscfg/<br />

• https://blog.coresecurity.com/2015/03/25/exploiting-cve-2015-0311-part-iibypassing-control-flow-guard-on-windows-8-1-update-3/<br />

• https://blog.coresecurity.com/2016/06/14/exploiting-internet-explorers-<br />

ms15-106-part-ii-jscript-arraybuffer-slice-memory-disclosure-cve-2015-<br />

6053/<br />

• https://labs.bromium.com/2015/09/28/an-interesting-detail-about-controlflow-guard/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!