iROP - Interesting ROP gadgets

SOURCE Boston 2015

Presented by: Xiaoning Li
Date: Wednesday May 27, 2015
Time: 10:00 - 10:40
Location: Washington
Track: Application Security

Today ROP based exploits are still very popular. Security solutions including EMET/KBouncer have designed different policies such as call-preceded ret location to detect/block ROP gadgets, at the same time control flow integrity becomes the popular proposal to solve ROP problem. But researcher finally found valid gadgets are still enough to create ROP chains. In this talk, we will discuss existing ROP defense approaches and evaluate new proposal like CFI/Shadow Stack with more powerful interesting gadgets.

Xiaoning Li


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats