Channel: LiveOverflow
Category: Education
Tags: sudo samedithow to exploit the heapliveoverflowheap analysisheap overflow tutorialgdb scriptheap allocationheap overflow vs stack overflowheap overflowexploitationlive overflowscriptinghacking tutorialgdb extensiondebuggingmemory corruptionbreakpointssudoheapfreeinformation security coursemallocpythonsegfaultsudoedithow to hackexploit tutorialsecurity researchgef extension
Description: We aren't getting anywhere... So we write a new tool to analyse the heap objects located after our overflowing buffer. Complete Playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx Grab the files: github.com/LiveOverflow/pwnedit (sorry, repo is a bit behind the videos) gef for gdb: github.com/hugsy/gef Episode 12: 00:00 - Intro 00:12 - How to Find Controllable Heap Allocations? 00:50 - Tracing free()! 01:21 - Finding Recognizable Strings on the Heap 01:58 - More Environment Variables 03:26 - fengshui2.py Script Changes 04:19 - Wrong Rabbit Hole... 05:20 - Some Other Research Attempts 06:47 - (gdb) gef Extension - Analyse the Heap Objects 09:03 - Heap Tracing Results 09:51 - Developing fengshui3.py 10:52 - First Peak at Script Results -=[ β€οΈ Support ]=- β per Video: patreon.com/join/liveoverflow β per Month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ π Social ]=- β Twitter: twitter.com/LiveOverflow β Instagram: instagram.com/LiveOverflow β Blog: liveoverflow.com β Subreddit: reddit.com/r/LiveOverflow β Facebook: facebook.com/LiveOverflow