Presentations for CanSecWest 2022

Andrea Mambretti, Anil Kurmus Robert Yuen Andrea Mambretti, Anil Kurmus Robert Yuen

Defeating Stack Canaries and Memory Safety with Speculative Execution

In this talk, we present a sub-class of transient execution attacks, we call SPEAR. This sub-class enables an attacker to repurpose memory corruption primitives that cannot be used in the context of traditional exploitation to achieve arbitrary memory read. In our talk, we discuss how SPEAR change the game in three main use-cases: control flow integrity (CFI), memory safety languages and stack smashing protectors (SSP) .

Read More