Channel: LiveOverflow
Category: Education
Tags: sudo samedithow to exploit the heapliveoverflowheap analysisheap overflow tutorialgdb scriptheap allocationheap overflow vs stack overflowheap overflowexploitationlive overflowscriptinghacking tutorialgdb extensiondebuggingmemory corruptionbreakpointssudoheapfreeinformation security coursemallocpythonsegfaultsudoedithow to hackexploit tutorialsecurity researchgef extension
Description: We aren't getting anywhere... So we write a new tool to analyse the heap objects located after our overflowing buffer. Complete Playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx Grab the files: github.com/LiveOverflow/pwnedit (sorry, repo is a bit behind the videos) gef for gdb: github.com/hugsy/gef Episode 12: 00:00 - Intro 00:12 - How to Find Controllable Heap Allocations? 00:50 - Tracing free()! 01:21 - Finding Recognizable Strings on the Heap 01:58 - More Environment Variables 03:26 - fengshui2.py Script Changes 04:19 - Wrong Rabbit Hole... 05:20 - Some Other Research Attempts 06:47 - (gdb) gef Extension - Analyse the Heap Objects 09:03 - Heap Tracing Results 09:51 - Developing fengshui3.py 10:52 - First Peak at Script Results -=[ ❤️ Support ]=- → per Video: patreon.com/join/liveoverflow → per Month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ 🐕 Social ]=- → Twitter: twitter.com/LiveOverflow → Instagram: instagram.com/LiveOverflow → Blog: liveoverflow.com → Subreddit: reddit.com/r/LiveOverflow → Facebook: facebook.com/LiveOverflow