SerenityOS: Writing a Full Chain Exploit
devcraft.io
devcraft.io
There are a number of things in this exploit you can no longer do in latest Serenity:
1. As the author mentioned, the entry point of this chain is fixed (the specific overflow problem in JSLib).
2. User libs have ASLR (edit: this used to say the kernel has a slide, but this is incorrect).
3. You can no-longer mprotect with PROT_EXEC after you create a writeable page (W^X)
4. This may or may not be relevant, but there is now a "blessed syscall pages" feature, preventing anyone except libc^h^h^h^h libSystem.so and a couple of other places from directly invoking syscalls, so you better find a few pages from libSystem or it will be a whole lot harder to reach out and touch someone with your exploit.
(Andreas and crew went on a month-or-so long security trek after a few CTFs and these changes plus quite a few others were the result.)
The kernel has a slide
Oh cool must have missed that, very nice :)
One small correction: the kernel does not yet have a slide, but everything else is accurate. Also, the blessed syscall pages is now down to a single page in in libsystem.so[1]
Furthermore, as of today[2] we also randomize the location of JavaScript heap memory, which makes the spray technique used in this exploit a lot less reliable as well :)
1. https://github.com/SerenityOS/serenity/commit/e87eac92730f1c...
2. https://github.com/SerenityOS/serenity/commit/e8d38567369253...