Skip to content

Latest commit

 

History

History
17 lines (14 loc) · 690 Bytes

README.md

File metadata and controls

17 lines (14 loc) · 690 Bytes

Heap Exploitation Study

설명

glibc ptmalloc allocator의 동작 원리를 분석하고, 힙 익스플로잇 기술을 공부합니다.

일정

  1. ptmalloc2 allocator, security check
  2. double free, fastbin dup + 문제
  3. fastbin dup consolidate, unsafe unlink + 문제
  4. memory leak, unsorted bin attack + 문제
  5. overlapping chunks, poison NULL byte, large bin attack + 문제
  6. house of lore, house of force + 문제

참고 자료

Heap Allocator Exploit, Dreamhack
Binary Exploitaion-Heap, ir0nestone
TechNote, Lazenca.0x0