Amy B @nyanbox.stackchk.fail · 12/01/2026Employing the Rite Of The Smashing Stack: We locate the Stack Address and a few Gadgets from the LIBC Library Then we overwrite the Stack with our terminale Gadget Chain. Returning To System. 100
Amy B @nyanbox.stackchk.fail · 12/01/2026With this Leak in hand I Forged an ArrayBuffer pointing to any Memory Address I knew the Name of. With this we can now manipulate the entire Memory Space at will. This makes the final Rite possible... 100
Amy B @nyanbox.stackchk.fail · 12/01/2026Leaking a Memory Address was the most difficult part! Eventually I realized I could read the Uninitialized padding inside heap allocations. Through heap manipulation this value could be a Pointer By overwriting the lowest byte with 00000101 the Pointer would be read as a Float 100
Amy B @nyanbox.stackchk.fail · 12/01/2026We can place Controlled-Data after the Array, which Splice will read Out-Of-Bounds This gives us the Rite Of The Type Forgery, allowing us to Forge an arbitrary Object if we know a Memory Address (to bypass ASLR) 100
Amy B @nyanbox.stackchk.fail · 12/01/2026The Fault derives from a "Time-of-Check Time-of-Use" in the Array.splice invocation. Splice checks bounds with the initial array Length (Time Of Check) In a Callback we can shrink the Array's Length. Then Splice uses the Cached Length, ignoring changes (Time Of Use) 100
Amy B @nyanbox.stackchk.fail · 12/01/2026When MicroQuickJS released, I spent 8.5 hours to summon an Exploit for it. Here is the Fault: var arr = new Array(30) var attack = { valueOf: function() { arr.length = 0 arr.length = 3 return 10 } } arr.splice(attack, 30) I document the full Ritual Process below 181