Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They’re a bit of a pain to implement but it might be worth doing…?


I wonder if they are actually possible. Remote code execution in the javascript engine does sound dangerous, but then you also have to get past address space randomisation, and then you need another exploit to escape the sandbox...


Right, all of which get patched every update as well. In theory chaining them together is doable, it’s just effort.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: