能力值:
( LV2,RANK:10 )
|
-
-
2 楼
自己找到方法了:
如下:
1:050> |
# 0 id: 56c attach name: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
. 1 id: 1364 attach name: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
2 id: 1030 attach name: C:\Windows\system32\browser_broker.exe
3 id: f2c attach name: C:\Windows\System32\RuntimeBroker.exe
1:050> |1s
ntdll!NtWaitForWorkViaWorkerFactory+0xa:
1:050> bp EDGEHTML!CSpliceTreeEngine::Init
1:050> g
可以成功断在断点处,
参考分析EDGE UAF的一篇文章,b35K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6Q4x3X3g2K6K9%4W2D9K9h3&6W2k6q4)9J5k6h3&6D9i4K6u0r3x3U0l9I4y4U0l9K6x3e0j5H3x3o6q4Q4x3X3g2Z5N6r3#2D9
PS:EDGE/IE11 的UAF,在MemGC下,都不属于安全问题,Fuzz越来越不容易了。
|
能力值:
( LV5,RANK:70 )
|
-
-
4 楼
UAF的洞,你不用gflags.exe开hpa和ust怎么搞啊。
|
|
|