DiscoverLiveOverflowThe Butterfly of JSObject - browser 0x02
The Butterfly of JSObject - browser 0x02

The Butterfly of JSObject - browser 0x02

Update: 2019-06-02
Share

Description

Let's have a look at how JavaScriptCore implements JavaScript Objects and values like integers and floats. We can use lldb to look into the memory.

Phrack: http://phrack.org/papers/attacking_javascript_engines.html
The Linus: https://twitter.com/linushenze
The Exploit: https://github.com/LinusHenze/WebKit-RegEx-Exploit
The Fix: https://bugs.webkit.org/show_bug.cgi?id=191731

-=[ πŸ•΄οΈAdvertisement ]=-

This video is supported by SSD Secure Disclosure: https://ssd-disclosure.com/
Offensive Security Conference TyphoonCon (10th - 14th June 2019): https://typhooncon.com/

-=[ πŸ”΄ Stuff I use ]=-

β†’ Microphone:* https://amzn.to/2LW6ldx
β†’ Graphics tablet:* https://amzn.to/2C8djYj
β†’ Camera#1 for streaming:* https://amzn.to/2SJ66VM
β†’ Lens for streaming:* https://amzn.to/2CdG31I
β†’ Connect Camera#1 to PC:* https://amzn.to/2VDRhWj
β†’ Camera#2 for electronics:* https://amzn.to/2LWxehv
β†’ Lens for macro shots:* https://amzn.to/2C5tXrw
β†’ Keyboard:* https://amzn.to/2LZgCFD
β†’ Headphones:* https://amzn.to/2M2KhxW

-=[ ❀️ Support ]=-

β†’ per Video: https://www.patreon.com/join/liveoverflow
β†’ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ πŸ• Social ]=-

β†’ Twitter: https://twitter.com/LiveOverflow/
β†’ Website: https://liveoverflow.com/
β†’ Subreddit: https://www.reddit.com/r/LiveOverflow/
β†’ Facebook: https://www.facebook.com/LiveOverflow/

-=[ πŸ“„ P.S. ]=-

All links with "*" are affiliate links.
LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#BrowserExploitation
CommentsΒ 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

The Butterfly of JSObject - browser 0x02

The Butterfly of JSObject - browser 0x02

LiveOverflow