tl;dr
- Create a sqlite3 extension with rce payload.
- Abuse werkzeug tempfile to upload the extension to server.
- load that extension using load_extension(‘/proc/self/fd/fd_no’);
tl;dr
tl;dr
LOAD
and S_TYPE
opcodes lead to OOB when addr > DRAM_BASE+DRAM_SIZE
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr