Writing FreeBSD Malware [video]
m.youtube.com
m.youtube.com
None of those suggested techniques address stack cookies but okay, I’ll keep listening.
“We can overwrite parts of the heap, the problem is the heap is not executable on amd64 and arm64”
And that’s where you’ve lost me. Processor has no concept of the “heap.” Whether or not you can make heap pages executable is up to the OS, and all common OS’s let you do this. Not only that, but the browser you’re using to view this very page is probably using executable allocations right now to JIT the (very little) JavaScript on this site.
Doesn’t strike me as a misunderstanding at all—my current cpu/os combo also doesn’t ship with an executable heap. This strikes me as lazy editing, but not a clear misunderstanding.
Is the hardenedbsd web site's security feature comparison table up to date?
Edited to remove comment about my confusion that Carolinacon14 -> 2014; not the case. It's 2018.
It's misleading, if not outright inaccurate.