A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2021; you can also visit the original URL.
The file type is application/pdf
.
NoJITsu: Locking Down JavaScript Engines
2020
Proceedings 2020 Network and Distributed System Security Symposium
unpublished
Data-only attacks against dynamic scripting environments have become common. Web browsers and other modern applications embed scripting engines to support interactive content. The scripting engines optimize performance via just-intime compilation. Since applications are increasingly hardened against code-reuse attacks, adversaries are looking to achieve code execution or elevate privileges by corrupting sensitive data like the intermediate representation of optimizing JIT compilers. This has
doi:10.14722/ndss.2020.24262
fatcat:56pwknobjvgmhi54yxtmxdcv5y