Why Nostr? What is Njump?
2025-04-12 20:16:20
in reply to

Zhuowei Zhang on Nostr: Actually, I'm wrong: once you overwrite the VID/PID from Extigy to FastTrackPro, you ...

Actually, I'm wrong: once you overwrite the VID/PID from Extigy to FastTrackPro, you can't trigger the Extigy overwrite again,

Even if you used the FastTrackPro to detect when your heap spray failed, you can't do anything to clean up, and you'll crash anyways on device disconnect.

So maybe they used the FastTrackPro because the out of bound access in `usb_set_configuration` is easier to exploit than the out of bound access->arbitrary free in `usb_destroy_configuration`?
Author Public Key
npub1cppa6rw8av0n2zjc6yarum7k0nmtkka4d7qas3ndy0sqpjfz9u0sx9e7uy