Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Hacking OpenAI(hacktron.ai ↗)
    33comments
  2. Astra for Law(openai.com ↗)
    429comments
  3. Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint(prismml.com ↗)
    106comments
  4. Waymo in Singapore(waymo.com ↗)
    9comments
  5. Bend – A language that blocks AI mistakes via proof, on CPU and GPU(bend-lang.com ↗)
    184comments
  6. Hister: A private search engine for the pages you visit and the files you keep(github.com/asciimoo ↗)
    141comments
  7. Alibaba releases Qwen 3.8 Omni Flash(qwen.ai ↗)
    24comments
  8. Wax motor(wikipedia.org ↗)
    57comments
  9. Pre-Greek: The lost language hidden within Ancient Greek(linguisticdiscovery.com ↗)
    discuss
  10. Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA(global.fujitsu ↗)
    205comments
  11. Telstra outage: The night a network decided the year was 2006(netnod.se ↗)
    10comments
  12. Shapelearn Qwen 3.8 27B (13.1 GB VRAM)(byteshape.com ↗)
    discuss
  13. Ask A Monk – A digital wilderness for thoughts with no immediate answer(askamonk.online ↗)
    10comments
  14. Apple detectives solved mystery of ancient tree and rewrote the history of fruit(scientificamerican.com ↗)
    discuss
  15. Code Scans(devin.ai ↗)
    2comments
  16. How to Write with an LLM(sockpuppet.org ↗)
    55comments
  17. Flet 1.0 – Build cross-platform apps in Python(flet.dev ↗)
    39comments
  18. Diplodocus, Long Thought Exclusively American, Turns Up in Spain(sci.news ↗)
    27comments
  19. The most important product decision is what you don't build(liamnugent.me ↗)
    23comments
  20. How Uber Protects Against Retry Storms(uber.com ↗)
    31comments
  21. I Put Nam A2-Lite Inside an iRig HD X(playtaurus.com ↗)
    4comments
  22. CrowdSec Source Code Leak(crowdsec.net ↗)
    42comments
  23. Khipu (Quipu) Field Guide(khipufieldguide.com ↗)
    discuss
  24. Why I didn’t sign the Fields medallists’ letter(gowers.wordpress.com ↗)
    331comments
  25. How do we prevent mathemathics from devolving into the Medieval Era of secrecy?(mathoverflow.net ↗)
    74comments
  26. Better Icon and Label Alignment(ishadeed.com ↗)
    2comments
  27. Infinite-Parameter LLMs: Generating and Adapting Weights from Live Data(arxiv.org ↗)
    38comments
  28. Rate limits on GitLab.com are changing(about.gitlab.com ↗)
    109comments
  29. Zettascale (YC S24) Is Hiring ASIC/FPGA Engineers to Build Chips for ASI(zscc.ai ↗)
    discuss
  30. The American Religion of Self-Storage Facilities(newyorker.com ↗)
    362comments

SerenityOS: Writing a Full Chain Exploit

86 pointsby 5y agodevcraft.io
9 comments
5y agoHN ↗

SerenityOS is an amazing project. Great videos, fun and interesting to watch and the os itself is surprisingly usable. Great example of modern C++.

5y agoHN ↗

I think the whole project is just so fun. I contributed a couple of patches and the whole community behind it is so warm and welcoming. Its incredibly pleasant and refreshing to interact with.

5y agoHN ↗

Looks like a lot went into this, i'm sure you must have been paid for your efforts with a bounty right?

5y agoHN ↗

Serenity is a great community to keep up with if you're interested in OS security (along with a whole lot of other topics that are typically buried in decades of incidental complexity).

There are a number of things in this exploit you can no longer do in latest Serenity:

1. As the author mentioned, the entry point of this chain is fixed (the specific overflow problem in JSLib).

2. User libs have ASLR (edit: this used to say the kernel has a slide, but this is incorrect).

3. You can no-longer mprotect with PROT_EXEC after you create a writeable page (W^X)

4. This may or may not be relevant, but there is now a "blessed syscall pages" feature, preventing anyone except libc^h^h^h^h libSystem.so and a couple of other places from directly invoking syscalls, so you better find a few pages from libSystem or it will be a whole lot harder to reach out and touch someone with your exploit.

(Andreas and crew went on a month-or-so long security trek after a few CTFs and these changes plus quite a few others were the result.)

5y agoHN ↗

Yeah a lot of work has happened in the few weeks since I started looking at this!

The kernel has a slide

Oh cool must have missed that, very nice :)

5y agoHN ↗

Indeed, I've had a ton of fun learning about system security by implementing various protection mechanisms and security mitigations (and doing some of my own exploits, too!) I'm learning new stuff all the time, so I've been growing the system's defenses along with my own skills.

One small correction: the kernel does not yet have a slide, but everything else is accurate. Also, the blessed syscall pages is now down to a single page in in libsystem.so[1]

Furthermore, as of today[2] we also randomize the location of JavaScript heap memory, which makes the spray technique used in this exploit a lot less reliable as well :)

1. https://github.com/SerenityOS/serenity/commit/e87eac92730f1c...

2. https://github.com/SerenityOS/serenity/commit/e8d38567369253...

5y agoHN ↗

Thanks Andreas. I've updated my comment to reflect those corrections.