Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
古典的なStack Overflow から JIT-ROPまで
Search
@tkmru
December 15, 2016
Programming
1
330
古典的なStack Overflow から JIT-ROPまで
ゼミにて
@tkmru
December 15, 2016
Tweet
Share
More Decks by @tkmru
See All by @tkmru
ipa-medit: Memory search and patch tool for IPA without Jailbreaking/ipa-medit-bh2022-europe
tkmru
0
280
Ipa-medit: Memory modification tool for iOS apps without Jailbreaking/ipa-medit-codeblue2022
tkmru
0
150
趣味と実益のための著名なOSSライブラリ起因の脆弱性の探求/seccamp2021-b5
tkmru
0
4.9k
Ipa-medit: Memory Search and Patch Tool for IPA Without Jailbreaking @Black Hat USA 2021 Arsenal/ipa-medit-bh2021-usa
tkmru
1
4.3k
Learn the essential way of thinking about vulnerabilities through post-exploitation on middlewares (MySQL/PostgreSQL編)/seccamp2020-b8
tkmru
3
840
apk-medit: memory search and patch tool for debuggable APK @CODE BLUE 2020 Bluebox
tkmru
0
190
apk-medit: memory search and patch tool for debuggable APK @Black Hat USA 2020 Arsenal/apk-medit-bh2020-usa
tkmru
0
4k
めんどうくさいゲームセキュリティ
tkmru
20
11k
Linux Rootkit Internals
tkmru
1
1.9k
Other Decks in Programming
See All in Programming
Amazon S3 NYJavaSIG 2024-12-12
sullis
0
100
nekko cloudにおけるProxmox VE利用事例
irumaru
3
430
Kaigi on Railsに初参加したら、その日にLT登壇が決定した件について
tama50505
0
100
return文におけるstd::moveについて
onihusube
1
1.1k
Scalaから始めるOpenFeature入門 / Scalaわいわい勉強会 #4
arthur1
1
330
モバイルアプリにおける自動テストの導入戦略
ostk0069
0
110
Webエンジニア主体のモバイルチームの 生産性を高く保つためにやったこと
igreenwood
0
340
これが俺の”自分戦略” プロセスを楽しんでいこう! - Developers CAREER Boost 2024
niftycorp
PRO
0
190
CSC305 Lecture 26
javiergs
PRO
0
140
テストケースの名前はどうつけるべきか?
orgachem
PRO
0
140
暇に任せてProxmoxコンソール 作ってみました
karugamo
2
720
PHPとAPI Platformで作る本格的なWeb APIアプリケーション(入門編) / phpcon 2024 Intro to API Platform
ttskch
0
250
Featured
See All Featured
Statistics for Hackers
jakevdp
796
220k
Side Projects
sachag
452
42k
GitHub's CSS Performance
jonrohan
1030
460k
How to train your dragon (web standard)
notwaldorf
88
5.7k
Stop Working from a Prison Cell
hatefulcrawdad
267
20k
Measuring & Analyzing Core Web Vitals
bluesmoon
4
170
Become a Pro
speakerdeck
PRO
26
5k
The Illustrated Children's Guide to Kubernetes
chrisshort
48
48k
GraphQLの誤解/rethinking-graphql
sonatard
67
10k
Raft: Consensus for Rubyists
vanstee
137
6.7k
The World Runs on Bad Software
bkeepers
PRO
65
11k
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
26
1.9k
Transcript
ݹయతͳ4UBDL0WFSqPX ͔Β +*5301·Ͱ θϛ !ULNSV
ؔݺͼग़࣌͠ͷελοΫ w DBMMGVODUJPOOBNF w ΞηϯϒϦͰDBMM໋ྩͰ͕ؔ͋ΔΞυϨεʹඈͿ w ͦͷࡍɺΓઌͷΞυϨεΛϦλʔϯΞυϨεͱͯ͠ ελοΫʹஔ͘ w ؔΛ࣮ߦ͠ऴ͑ΔͱSFU໋ྩͰϦλʔϯΞυϨεʹΔ
w DBMMGVODUJPOOBNFΛ࣮ߦͨ͠ͱ͖ͷ ɹɹɹɹɹɹɹɹɹɹɹɹɹελοΫͷ༷ࢠ ม ม ϦλʔϯΞυϨε
PWFSqPX͢Δίʔυྫ w ಡΈࠐΈαΠζΛνΣοΫ͠ͳ͍ؔΛ͍ͬͯΔͱ PWFSqPXͷݪҼͱͳΔ w FY TUSDQZ HFUT
4UBDL0WFSqPX w PWFSqPXͤ͞ɺ࣮ߦ͍ͨ͠ίʔυΛελοΫʹॻ͖ࠐΉ w ͦͷࡍɺϦλʔϯΞυϨεΛ࣮ߦ͍ͨ͠ίʔυ͕͋Δ ΞυϨεʹॻ͖͑Δ w ॻ͖͑ΒΕͨΞυϨεʹ͋Δίʔυ͕࣮ߦ͞ΕΔ CVG<> PME
ϦλʔϯΞυϨε BBBB BBBB BBBB BBBB Y PWFSqPX͢ΔલͷελοΫͷ༷ࢠ PWFSqPXͨ͠ޙͷελοΫͷ༷ࢠ
ରࡦͷҰྫ w $16ͷ/9CJU /PF9FDVUFCJU w ελοΫʹ࣮ߦͰ͖ͳ͍ྖҬΛ࡞Δ w ࣮ྫʣ-JOVY&YFD4IJFMEɺ8JO%&1 w
PWFSqPXʹΑΓελοΫ্ʹ߈ܸίʔυΛஔ͞Εͯ ελοΫ্ͷίʔυ࣮ߦͰ͖ͳ͍
301 w 3FUVSO0SJFOUFE1SPHSBNNJOH w /9CJU༗ޮԼͰTUBDL্ͷίʔυΛ࣮ߦͰ͖ͳ͍ w ͔͠͠ɺ࣮ߦՄೳͳྖҬ FYϥΠϒϥϦ ͋Δ w
࣮ߦՄೳͳྖҬͷதͰ͑ͦ͏ͳίʔυΛ அยతʹݺͼग़͢͜ͱͰҙͷಈ࡞Λͤ͞Δ͜ͱ͕ Ͱ͖Δ
w 301Ͱར༻͢Δஅยతͳίʔυͷ͜ͱΛ301HBEHFUͱ ݺͿ w SFU໋ྩ͕ޙΖʹ͍͍ͭͯΔίʔυ w FY QPQSEJSFU w SFU໋ྩΛ࣮ߦ͠Ϧλʔϯ͢ΔஅยతͳίʔυΛ
ෳݺͿ͜ͱͰతͷಈ࡞Λୡ͢Δ͜ͱ͔Β 3FUVSO0SJFOUFE1SPHSBNNJOHͱ໊͚ΒΕͨ 301
FYQMPJUͷྫ w ϦλʔϯΞυϨεΛҎԼͷॱͰॻ͖͑Δ w TZTUFN lCJOTIz Λ࣮ߦ͠γΣϧΛىಈ w QPQSEJSFUͷΞυϨεҾΛηοτ͢Δ w
ελοΫʹCJOTIͷΞυϨεΛੵΜͰ͓͘ w DBMMTZTUFN ͷΞυϨεTZTUFN ΛݺͿ
301ͷσϞ
ରࡦͷҰྫ w "4-3 "EESFTT4QBDF-BZPVU3BOEPNJ[BUJPO w ΞυϨεۭؒஔΛϥϯμϜʹ͢Δ w ελοΫɺώʔϓɺσʔλྖҬͷΞυϨε͕ϥϯμϜʹ w
ܾΊଧͪͰΞυϨεΛࢦఆ͢Δ߈ܸΛແޮԽͰ͖Δ
"4-3 -JOVY ͷ w (05ͷΞυϨε͕ݻఆͷ·· w (05 (MPCBM0⒎TFU5BCMF w
γϯϘϧ ؔ ͷϙΠϯλͷྻ w ؔͷΞυϨεΛղܾ͢ΔͨΊͷྖҬ
+*5301 w +VTU*O5JNF301 w (05ʹొ͞Ε͍ͯΔؔΛͬͯɺ࣮ߦதʹ ࣮ߦՄೳྖҬΛಡΈऔΔ w ಡΈऔͬͨྖҬʹ͋Δ301HBEHFUΛ͏ w ΞυϨε͕ϥϯμϜԽ͞Εͨ͋ͱʹಡΈऔΔ͜ͱͰɹ
"4-3Λճආ
+*5301ͷରࡦ w ͍Ζ͍Ζจ͕ग़͍ͯΔ͕ɺ࣮ࡍʹ04ίϯύΠϥʹ࣮ ͞Εͨͷݱ࣌Ͱͳ͍ɻ w ࠓޙɺࢹ͍͖͍ͯͨ͠
ࢀߟจݙ w "OUJ301ࡇΓͩͥʂ64&/*94FDVSJUZ301 3FUVSOPGUIFFEJZV[VIBSBͷه IUUQZV[VIBSBIBUFOBCMPHKQFOUSZ w +*5301؇ख๏)FJTFOCZUFʹ͍ͭͯ·ͱΊͯΈΔ ͍ΖςΫϊϩδʔIUUQJOB[IBUFOBCMPHDPN FOUSZ