[tor-bugs] #10281 [Tor Browser]: Investigate usage of alternate memory allocators and memory hardening options

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Aug 19 14:02:28 UTC 2014


#10281: Investigate usage of alternate memory allocators and memory hardening
options
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:
  mikeperry              |     Status:  new
         Type:           |  Milestone:
  enhancement            |    Version:
     Priority:  major    |   Keywords:  gitian, tbb-security-hardening,
    Component:  Tor      |  tbb-firefox-patch
  Browser                |  Parent ID:
   Resolution:           |
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------

Comment (by tom):

 For lack of a better place to store these, here are some good blog posts
 on IE's technique(s):

  * http://researchcenter.paloaltonetworks.com/2014/07/beginning-end-use-
 free-exploitation/
  * https://labs.mwrinfosecurity.com/blog/2014/06/20/isolated-heap-friends
 ---object-allocation-hardening-in-web-browsers/
  * http://blog.fortinet.com/post/is-use-after-free-exploitation-dead-the-
 new-ie-memory-protector-will-tell-you

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10281#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list