
A repository for learning various heap exploitation techniques.
This repo is for learning various heap exploitation techniques.
We use Ubuntu's Libc releases as the gold-standard. Each technique is verified to work on corresponding Ubuntu releases.
You can run apt source libc6 to download the source code of the Libc you are using on a Debian-based operating system. You can also click ▶️ to debug the technique in your browser using gdb.
We came up with the idea during a hack meeting, and have implemented the following techniques:
| File | ▶️ | Technique | Glibc-Version | Patch | Applicable CTF Challenges |
|---|---|---|---|---|---|
| first_fit.c | Demonstrating glibc malloc's first-fit behavior. | ||||
| calc_tcache_idx.c | Demonstrating glibc's tcache index calculation. | ||||
| fastbin_dup.c | ▶️ | Tricking malloc into returning an already-allocated heap pointer by abusing the fastbin freelist. | < 2.43 | patch | |
| fastbin_dup_into_stack.c | ▶️ | Tricking malloc into returning a nearly-arbitrary pointer by abusing the fastbin freelist. | < 2.43 | patch | 9447-search-engine, 0ctf 2017-babyheap |
| fastbin_dup_consolidate.c | ▶️ | Tricking malloc into returning an already-allocated heap pointer by putting a pointer on both fastbin freelist and the top chunk. | < 2.43 | patch | Hitcon 2016 SleepyHolder |
| unsafe_unlink.c | ▶️ | Exploiting free on a corrupted chunk to get arbitrary write. | latest | HITCON CTF 2014-stkof, Insomni'hack 2017-Wheel of Robots | |
| house_of_spirit.c | ▶️ | Frees a fake fastbin chunk to get malloc to return a nearly-arbitrary pointer. | latest | hack.lu CTF 2014-OREO | |
| poison_null_byte.c | ▶️ | Exploiting a single null byte overflow. | latest | PlaidCTF 2015-plaiddb, BalsnCTF 2019-PlainNote | |
| house_of_lore.c | ▶️ | Tricking malloc into returning a nearly-arbitrary pointer by abusing the smallbin freelist. | latest | ||
| overlapping_chunks.c | ▶️ | Exploit the overwrite of a freed chunk size in the unsorted bin in order to make a new allocation overlap with an existing chunk | < 2.29 | patch | hack.lu CTF 2015-bookstore, Nuit du Hack 2016-night-deamonic-heap |
| overlapping_chunks_2.c | ▶️ | Exploit the overwrite of an in use chunk size in order to make a new allocation overlap with an existing chunk | < 2.29 | patch | |
| mmap_overlapping_chunks.c | Exploit an in use mmap chunk in order to make a new allocation overlap with a current mmap chunk | latest | |||
| house_of_force.c | ▶️ | Exploiting the Top Chunk (Wilderness) header in order to get malloc to return a nearly-arbitrary pointer | < 2.29 | patch | Boston Key Party 2016-cookbook, BCTF 2016-bcloud |
| unsorted_bin_into_stack.c | ▶️ | Exploiting the overwrite of a freed chunk on unsorted bin freelist to return a nearly-arbitrary pointer. | < 2.29 | patch |