I'm wondering if there is an educational collection of examples on how security on the JVM was compromised in old versions.
After reading a bit of the articles on the IKVM blog, I have the feeling that I learn more by understanding past cases of security issues instead of reading some plain "Do's and Dont's" (looks like most of the interesting articles have been pulled, what a shame).
Is there something like that available somewhere?
Maybe I have too strong expectations: I don't care about some script-kiddy stuff, but I'm looking for quality content going into the depth about
Is there something like that available on the net?
I think there is very little research on JVM exploits. What do you want to do exactly?
Often, breaking out of the browser sandbox is trivial and has nothing to do with the JVM itself: http://jouko.iki.fi/adv/javaplugin.html
The best information will be available from an open-source JVM like BlackDown. Search the SVN changelog for the words 'exploit', 'bug', 'sandbox' and look at the SVN Diff's.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With