Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Am I reading it correctly that it's possible to invoke syscalls from Javascript? That seems like a monumentaly bad idea...


No, that's just a library they made that uses a WebKit exploit to invoke a ROP chain to run syscalls.


Not directly. The exploit referred to by the title is a kernel exploit, but to execute the kernel exploit you need to be able to already run user code. They're using a Webkit exploit to run their user code.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: