Good news everyone, I found a usable crash. I was able to crash cvm and smash the stack. However, gdb fails to behave on the Kindle, so I'm still trying to find the exact data of the stack (so I can write a payload). It also sucks because cvm does not dump the registers and stack on crash, so I have to manually dump the memory.
Last edited by yifanlu; 11-20-2011 at 04:17 PM.
|