"Scudo Allocator exploitation" - Zac Ecob, BSides Canberra 2023

  Рет қаралды 225

BSides Canberra

BSides Canberra

5 ай бұрын

The Scudo allocator is a memory allocator designed primarily for C/C++. Designed as part of the LLVM project, it has gained popularity as an alternative choice to allocators like ptmalloc2, most prominently being used as Android's default allocator since Android 11. Scudo aims to provide efficient memory allocation and deallocation whilst mitigating common vulnerabilities such as heap buffer overflows, use-after-frees, and double frees. As the risk associated with these vulnerabilities continues to rise, scudo is primed to become more and more of a prominent choice for developers to use.
This talk will cover a high-level overview of the current, as well as completely new, exploitation techniques related to the scudo allocator. We will run through the inner workings of the allocator, looking at security-based design choices such as quarantine regions, randomized allocation, red-zone regions, and hardened headers. Then, we'll review the existing research for exploiting the allocator, before demonstrating completely new techniques that expand what scenarios are possible to exploit. Attendees will gain a proper understanding of the motivations behind scudo's design choices, and the go-to techniques for exploiting the allocator.
Zac Ecob
Second year computer science student @ UNSW. Binary nerd. Occasionally play CTFs for teams like Blitzkreig and Water Paddler. Have previously talked at conferences such as Bsides Sydney and Scones, mainly revolving around kernel exploitation.

Пікірлер
"Locks on the wire" by Eldar Marcussen, BSides Canberra 2023
32:19
BSides Canberra
Рет қаралды 104
"APT Attack Techniques in Azure Cloud" by Lina Lau, BSides Canberra 2023
23:15
I CAN’T BELIEVE I LOST 😱
00:46
Topper Guild
Рет қаралды 120 МЛН
아이스크림으로 체감되는 요즘 물가
00:16
진영민yeongmin
Рет қаралды 57 МЛН
i wrote my own memory allocator in C to prove a point
5:23
Low Level Learning
Рет қаралды 355 М.
Samsung Galaxy Unpacked July 2024: Official Replay
1:8:53
Samsung
Рет қаралды 23 МЛН
Мой инст: denkiselef. Как забрать телефон через экран.
0:54
Choose a phone for your mom
0:20
ChooseGift
Рет қаралды 7 МЛН
Hisense Official Flagship Store Hisense is the champion What is going on?
0:11
Special Effects Funny 44
Рет қаралды 3,2 МЛН
$1 vs $100,000 Slow Motion Camera!
0:44
Hafu Go
Рет қаралды 23 МЛН