Keynote记忆安全语言救不了你

3.0 2025-05-10 75 0 1327 KB 21 页 PDF
侵权投诉
Keynote记忆安全语言救不了你
Keynote记忆安全语言救不了你
Keynote记忆安全语言救不了你
Keynote记忆安全语言救不了你
Keynote记忆安全语言救不了你
摘要:

Memory SafeLanguages Won’t Save YouYarden ShafirAbout me•Security Engineer & Researcher•Windows Internals researcher•Former EDR developer•Likes to research exploits, mitigations and post-exploitation techniques•Former circus artistMemory Bugs are Everywhere•~70% of reported software bugs are memory bugsGoogle Chrome analysis, 2015-2020Microsoft analysis, 2006-2018Presented by Matt Miller at BlueHatIL2019Microsoft CVEs root cause2015-2023Software Memory Safety•A lot of new code is written in Rust, Go, C#•But it’s not always written very well•In 2023 CISA issued an advisory for “The Urgent Need for Memory Safety in Software Products”•Encourages companies to use memory safe languages in future projects•Microsoft is (re)writing some components in rust•Some parts of Win32k, Sudo, OpenVMMWill Memory Safety Kill Exploitation?•Nope•Memory safe != Bug free•Memory safe languages still contain “unsafe” code blocks•Memory safe languages defend againstmemory vulnerabilities•Attackers are already mo

展开>> 收起<<
Keynote记忆安全语言救不了你

共 21 页,预览3页

还剩18页未读, 继续阅读

声明:企商查报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
作者: 分类: 属性:21 页 大小:1327 KB 格式:PDF 时间:2025-05-10

开通VIP享超值会员特权

  • 多端同步记录
  • 高速下载文档
  • 免费文档工具
  • 分享文档赚钱
  • 每日登录抽奖
  • 优质衍生服务
/ 3
客服
关注