DiscoverLiveOverflowRevisiting JavaScriptCore Internals: boxed vs. unboxed
Revisiting JavaScriptCore Internals: boxed vs. unboxed

Revisiting JavaScriptCore Internals: boxed vs. unboxed

Update: 2019-06-30
Share

Description

Part 6: There are still many things I haven't explained yet. So in this video we go over the boxed vs. unboxed values, how to convert Integer addresses to Doubles and why our bug is a memory corruption.

blog: https://liveoverflow.com/revisiting-javascriptcore-internals-boxed-vs-unboxed-browser-0x06/
test.js: https://gist.github.com/LiveOverflow/71bcf3f364c9719998bf159923310019
The Exploit:https://github.com/LinusHenze/WebKit-RegEx-Exploit

Playlist: https://www.youtube.com/watch?v=5tEdSoZ3mmE&list=PLhixgUqwRTjwufDsT1ntgOY9yjZgg5H_t

-=[ πŸ•΄οΈAdvertisement ]=-

This video is supported by SSD Secure Disclosure: https://ssd-disclosure.com/
Offensive Security Conference TyphoonCon: https://typhooncon.com/
Challenge: https://typhooncon.com/typhooncon-challenge-2019/

-=[ πŸ”΄ Stuff I use ]=-

β†’ Microphone:* https://amzn.to/2LW6ldx
β†’ Graphics tablet:* https://amzn.to/2C8djYj
β†’ Camera#1 for streaming:* https://amzn.to/2SJ66VM
β†’ Lens for streaming:* https://amzn.to/2CdG31I
β†’ Connect Camera#1 to PC:* https://amzn.to/2VDRhWj
β†’ Camera#2 for electronics:* https://amzn.to/2LWxehv
β†’ Lens for macro shots:* https://amzn.to/2C5tXrw
β†’ Keyboard:* https://amzn.to/2LZgCFD
β†’ Headphones:* https://amzn.to/2M2KhxW

-=[ ❀️ Support ]=-

β†’ per Video: https://www.patreon.com/join/liveoverflow
β†’ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ πŸ• Social ]=-

β†’ Twitter: https://twitter.com/LiveOverflow/
β†’ Website: https://liveoverflow.com/
β†’ Subreddit: https://www.reddit.com/r/LiveOverflow/
β†’ Facebook: https://www.facebook.com/LiveOverflow/

-=[ πŸ“„ P.S. ]=-

All links with "*" are affiliate links.
LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.
CommentsΒ 
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Revisiting JavaScriptCore Internals: boxed vs. unboxed

Revisiting JavaScriptCore Internals: boxed vs. unboxed

LiveOverflow