|
|
|
|
|
by rinon
3716 days ago
|
|
I'm not affiliated with Copperhead at all, but I am familiar with the sorts of techniques they are using. Exploit mitigations, such as Address Space Layout Randomization, Control-Flow Integrity, Fine-grained Randomization, etc. provide a layer of hardening to make exploitation of a source code vulnerability harder, or even not possible on the protected device. The bug (zero-day) still exists, it's just not as exploitable to do bad stuff. |
|
https://copperhead.co/blog/2015/06/11/android-pax
https://copperhead.co/blog/2015/07/27/hardening-bionic
https://copperhead.co/blog/2015/05/11/aslr-android-zygote