Android mediaserver exploit – heap thermal vision
bits-please.blogspot.com
Android mediaserver exploit – heap thermal vision
1–8 of 8 posts
Re: Android mediaserver exploit – heap thermal vision
#2Also, nice map.
Re: Android mediaserver exploit – heap thermal vision
#3That's a really nice explanation of security topics. It concisely explains the tough stuff without being dumbed down or hand-waving away the complex bits. That's rare. A lot of exploit documentation has a "leet" feel to it, or at least a condescending and dismissive tone (particularly toward the developers of the software being exploited) that I find off-putting. Also, nice map.
Re: Android mediaserver exploit – heap thermal vision
#4Re: Android mediaserver exploit – heap thermal vision
#5Re: Android mediaserver exploit – heap thermal vision
#6Is there any chance that ASLR would put libcamera_client.so in a lower memory location than get_input_buffer_size so you couldn't increment the pointer to reach it?
Re: Android mediaserver exploit – heap thermal vision
#7Great write up. But does this mean that Google doesn't hold themselves to project zero's 90 days before disclosure? (Or have they realized that 90 days really isn't enough time?)
Re: Android mediaserver exploit – heap thermal vision
#8Great write up. But does this mean that Google doesn't hold themselves to project zero's 90 days before disclosure? (Or have they realized that 90 days really isn't enough time?)
In this case, it seems so. However, I must say I've reported many vulnerabilities to Google since and they've all been handled within that time-frame.