GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
11–20 of 209 posts
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#12Tested on three Android devices (version 9, 13, 16) with different Firefox versions under 150 (had to modify for older). Two boot looped, I had to enter recovery and the other just powered off [0]. The demo modifies the wallpaper on supported Pixel devices. [0] IonStack https://rootme.nebusec.ai ____ Tip: Install a Chromium flavor browser (Chromite) separate from the main browser. Disable Javascript and hardware acce…
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#13Forgot to include "LPE" (local...) in the title so most of us can get back to weekending.
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#14A what?
It's not so widely used and it's not explained in the first couple screenfuls of TFA (which by itself is weirdly structured, taking entire paragraphs to explain when it was introduced, when it was discovered, etc. before even explaining what it actually is).
Of course the title was chosen when the article was first published on a site dedicated to security, where probably everyone knows it. This suggests that insisting on unmodified titles when republishing in HN is a poor rule.
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#15Forgot to include "LPE" (local...) in the title so most of us can get back to weekending.
Since this enables container escape, sounds like this might still impact quite a lot of us?
I would have hoped that only a few of us are so misinformed as to do that.
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#16Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#17A what?
I'm glad someone else asked. :) It's not so widely used and it's not explained in the first couple screenfuls of TFA (which by itself is weirdly structured, taking entire paragraphs to explain when it was introduced, when it was discovered, etc. before even explaining what it actually is). Of course the title was chosen when the article was first published on a site dedicated to security, where probably everyone know…
Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#18Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#19Re: GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years
#20Has anyone in infosec ever seen the term "use after free" before LLMs? Or is this basically an acronym claude invented? I say this because I see claude use this term all the time like its common knowledge but in 15+ years in tech never seen it myself. I've seen all kinds of terms used to describe memory errors: memory corruption, heap corruption, stack corruption, whatever, just never this acronym.