Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / JavaScript-based ASLR bypass attack simplifies browser exploits

JavaScript-based ASLR bypass attack simplifies browser exploits

Latest Govt. Jobs 16:42:00 News Edit
The AnC attack could spell the death of ASLR in browsers.

Researchers have devised a new attack that can bypass one of the main exploit mitigations in browsers: address space layout randomization (ASLR). The attack takes advantage of how modern processors cache memory and, because it doesn't rely on a software bug, fixing the problem is not easy.
Researchers from the Systems and Network Security Group at Vrije Universiteit Amsterdam (VUSec) unveiled the attack, dubbed AnC, Wednesday after having coordinated its disclosure with processor, browser and OS vendors since October.
ASLR is a feature present in all major operating systems. Applications, including browsers, take advantage of it to make the exploitation of memory corruption vulnerabilities like buffer overflows more difficult.
The mitigation technique involves randomly arranging the memory address space positions used by a process so that attackers don't know where to inject malicious code so that the process executes it.
There are methods to bypass ASLR, but they often involve chaining multiple vulnerabilities together, including one that allows for memory disclosure. This new attack removes the need for such additional vulnerabilities, making the exploitation of remote code execution bugs much easier.
"This new attack is indeed very interesting if as efficient and reliable as reported," said Carsten Eiram, the chief research officer at vulnerability intelligence firm Risk Based Security, via email. "It can be chained with many code execution type vulnerabilities across different platforms and even different software that supports JavaScript, e.g. browsers. On top of that, it seems to pretty quickly allow breaking ASLR, so it is seems practical in real life and not just theoretical or academic."
What makes the attack interesting is that it does not depend on any particular software feature. It takes advantage of the way in which the memory management unit (MMU) of modern processors perform memory caching to improve performance.
It turns out that this can be used as a side channel directly from JavaScript to leak heap and code pointers that ASLR is supposed to hide.
The same researchers devised a different ASLR bypass attack last year that worked against Microsoft Edge. That attack relied on a software feature called memory deduplication that Microsoft later disabled to protect users.
That's not possible in case of AnC, because the core of the problem is at the hardware level and can't be fixed in existing CPUs. However, browser vendors can make certain tweaks that would make the implementation of the attack harder.
For example, the attack requires a precise timer in JavaScript, and browser vendors previously disabled one function that could be used for similar cache timing attacks. The VUSec researchers found two new ways to build the timers used by AnC, so browser vendors could now block these too. However, there's no guarantee that other methods won't be found in the future.
The researchers suggested several changes to CPU, OS and browser vendors that could make AnC-like attacks harder to pull off, but some of them might have performance implications that need to be further investigated. So far, the Apple Product Security Team worked with the researchers to harden WebKit against the AnC attack.
"The problem is fundamental as it is in hardware and cannot be completely eradicated with software countermeasures," said Cristiano Giuffrida, an assistant professor at VU Amsterdam and one of AnC's authors, via email. "And even hardware countermeasures are perhaps too expensive to consider to save ASLR (as hinted by some hardware vendors we talked to)."
If this is not the last nail in ASLR's coffin, it's very much the last nail in the coffin for ASLR as we know it, Giuffrida said.
AnC might have implications beyond browsers, even though browsers are the most obvious target because of the wide use of JavaScript on the Web. However, any software that allows the execution of JavaScript code is potentially vulnerable, including PDF readers.
It's not clear if this attack will lead to a resurgence of browser exploits. For the past several years, the exploit kits that are used in large-scale, drive-by download attacks have mainly focused on targeting vulnerabilities in browser plug-ins like Flash Player, Java or Silverlight instead of flaws in the browsers themselves.
Time will tell, but bypassing ASLR is just one of the exploitation puzzle, Eiram said. Browsers have other security mechanisms in place, like sandboxes, that also need to be defeated to achieve arbitrary code execution, he said.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Oppo F7 India launch confirmed

Alcatel 1x with Android Oreo (Go ed...

Huawei P20, P20 Pro, P20 Lite price
JavaScript-based ASLR bypass attack simplifies browser exploits JavaScript-based ASLR bypass attack simplifies browser exploits Reviewed by Latest Govt. Jobs on 16:42:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • How to Free Up iCloud Storage Space
    How to Free Up iCloud Storage Space
    05.03.2017 - 0 Comments
    Apple offers 5 GB of free iCloud space to everyone, but you’ll run up against that storage limit sooner…
  • What Is Cloudflare, and Did It Really Leak My Data All Over the Internet?
    What Is Cloudflare, and Did It Really Leak My Data All Over the Internet?
    26.02.2017 - 0 Comments
    Over the past few months, a bug in the popular Cloudflare service may have exposed sensitive user…
  • LG K7 LTE Review
    LG K7 LTE Review
    24.06.2016 - 0 Comments
    LG K7 LTE Review: In India LG recently launched the K7 LTE and K10 LTE, from the series of its new…
  • What is the best Linux distro for beginners?
    What is the best Linux distro for beginners?
    13.02.2017 - 0 Comments
    Note: Our best Linux distro for beginners feature has been fully updated. This article was…
  • Explore the galaxy in full 3D with Celestia
    Explore the galaxy in full 3D with Celestia
    11.03.2017 - 0 Comments
    There are lots of free space exploration programs around, but Celestia is one…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...

Random Posts

  • Motorola’s 3rd anniversary in India: Top deals on Moto Z, Moto M, Moto Mods and more
    Motorola’s 3rd anniversary in India: Top deals on Moto Z, Moto M, Moto Mods and more
    20.02.2017 - 0 Comments
    Flipkart is offering deals on Moto e3 Power, Moto M, Moto Z, Moto Z Play, Moto G Turbo Edition, Moto E2,…
  • Top 10 PS4 accessories: All the extras you need to very own on your PS4
    Top 10 PS4 accessories: All the extras you need to very own on your PS4
    16.03.2017 - 0 Comments
    While you can have plenty of fun with the PlayStation 4 right out of the box – and some…
  • What type of smarthome devices am i able to use if i lease an rental?
    What type of smarthome devices am i able to use if i lease an rental?
    06.01.2018 - 0 Comments
    Upgrading to a smart home used to be exclusively the realm of homeowners. If you couldn’t run cables,…
  • Brand Really Matter When Buying a Hard Drive
    Brand Really Matter When Buying a Hard Drive
    12.03.2017 - 0 Comments
    When it comes to hard drives, everyone seems to have a horror story about one brand or another that…
  • Now 20 lakh 'poor families' to get free internet connections in Kerala
    Now 20 lakh 'poor families' to get free internet connections in Kerala
    04.03.2017 - 0 Comments
    Internet would be made the right of the people and two million "poor families" will get free access to…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!