Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
how2heap — 一个用于学习各种堆利用技术的仓库。 | Kitploit
工具/GitHubGitHub/shellphish/how2heap
漏洞利用CTF学习与教育精选资源二进制利用实验室与实践二进制利用 分类第 4 名CTF 分类第 7 名
GitHubshellphish/how2heap

how2heap

一个用于学习各种堆利用技术的仓库。

8.8k1.3k304个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
# 堆利用教学

本仓库用于学习各种堆利用技术。
我们以 Ubuntu 的 Libc 发行版作为黄金标准。每种技术都已在对应的 Ubuntu 发行版上验证有效。
你可以在基于 Debian 的操作系统上运行 `apt source libc6` 下载你正在使用的 Libc 源码。你也可以点击 :arrow_forward: 使用 gdb 在浏览器中调试该技术。

我们是在一次黑客聚会上想到这个主意的,并已实现了以下技术:

| 文件 | :arrow_forward: | 技术 | Glibc 版本 | 补丁 | 适用的 CTF 挑战题 |
|------|-----|-----------|---------------|-------|---------------------------|
| [first_fit.c](https://github.com/shellphish/how2heap/blob/master/first_fit.c) | |  演示 glibc malloc 的 first-fit 行为。 | | | |
| [calc_tcache_idx.c](https://github.com/shellphish/how2heap/blob/master/calc_tcache_idx.c)| |  演示 glibc 的 tcache 索引计算。| | | |
| [fastbin_dup.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/fastbin_dup.c) | <a href="https://wargames.ret2.systems/level/how2heap_fastbin_dup_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 通过滥用 fastbin 空闲链表,欺骗 malloc 返回一个已分配的堆指针。 | < 2.43 | [patch](https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=malloc/malloc.c;h=fa854fc4b8f75b09902ea7ed1180487beb6e4683;hp=7811152d9d9eba3e0f0a3416d9944cc142caaafe;hb=bf1015fb2d7e4057925481960626533f8571a2fb;hpb=e3062b06c5767f672baf9574c4d7cbebf7d0ee6e) | | |
| [fastbin_dup_into_stack.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/fastbin_dup_into_stack.c) | <a href="https://wargames.ret2.systems/level/how2heap_fastbin_dup_into_stack_2.23" title="Debug Technique In Browser">:arrow_forward:</a> | 通过滥用 fastbin 空闲链表,欺骗 malloc 返回一个几乎任意的指针。 | < 2.43 | [patch](https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=malloc/malloc.c;h=fa854fc4b8f75b09902ea7ed1180487beb6e4683;hp=7811152d9d9eba3e0f0a3416d9944cc142caaafe;hb=bf1015fb2d7e4057925481960626533f8571a2fb;hpb=e3062b06c5767f672baf9574c4d7cbebf7d0ee6e) | [9447-search-engine](https://github.com/ctfs/write-ups-2015/tree/master/9447-ctf-2015/exploitation/search-engine), [0ctf 2017-babyheap](https://web.archive.org/web/20181104155842/http://uaf.io/exploitation/2017/03/19/0ctf-Quals-2017-BabyHeap2017.html) |
| [fastbin_dup_consolidate.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/fastbin_dup_consolidate.c) | <a href="https://wargames.ret2.systems/level/how2heap_fastbin_dup_consolidate_2.23" title="Debug Technique In Browser">:arrow_forward:</a> | 通过将一个指针同时放入 fastbin 空闲链表和 top chunk,欺骗 malloc 返回一个已分配的堆指针。 | < 2.43 | [patch](https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=malloc/malloc.c;h=fa854fc4b8f75b09902ea7ed1180487beb6e4683;hp=7811152d9d9eba3e0f0a3416d9944cc142caaafe;hb=bf1015fb2d7e4057925481960626533f8571a2fb;hpb=e3062b06c5767f672baf9574c4d7cbebf7d0ee6e) | [Hitcon 2016 SleepyHolder](https://github.com/mehQQ/public_writeup/tree/master/hitcon2016/SleepyHolder) |
| [unsafe_unlink.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/unsafe_unlink.c) | <a href="https://wargames.ret2.systems/level/how2heap_unsafe_unlink_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对被破坏 chunk 的 free 操作实现任意写。 | 最新 | | [HITCON CTF 2014-stkof](http://acez.re/ctf-writeup-hitcon-ctf-2014-stkof-or-modern-heap-overflow/), [Insomni'hack 2017-Wheel of Robots](https://gist.github.com/niklasb/074428333b817d2ecb63f7926074427a) |
| [house_of_spirit.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/house_of_spirit.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_spirit_2.23" title="Debug Technique In Browser">:arrow_forward:</a> | 释放一个伪造的 fastbin chunk,使 malloc 返回一个几乎任意的指针。 | 最新 | | [hack.lu CTF 2014-OREO](https://github.com/ctfs/write-ups-2014/tree/master/hack-lu-ctf-2014/oreo) |
| [poison_null_byte.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/poison_null_byte.c) | <a href="https://wargames.ret2.systems/level/how2heap_poison_null_byte_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 利用单个 null 字节溢出。 | 最新 | | [PlaidCTF 2015-plaiddb](https://github.com/ctfs/write-ups-2015/tree/master/plaidctf-2015/pwnable/plaiddb), [BalsnCTF 2019-PlainNote](https://gist.github.com/st424204/6b5c007cfa2b62ed3fd2ef30f6533e94?fbclid=IwAR3n0h1WeL21MY6cQ_C51wbXimdts53G3FklVIHw2iQSgtgGo0kR3Lt-1Ek)|
| [house_of_lore.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/house_of_lore.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_lore_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 通过滥用 smallbin 空闲链表,欺骗 malloc 返回一个几乎任意的指针。 | 最新 | | |
| [overlapping_chunks.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.27/overlapping_chunks.c) | <a href="https://wargames.ret2.systems/level/how2heap_overlapping_chunks_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对 unsorted bin 中已释放 chunk 大小的覆盖,使新分配与现有 chunk 重叠。 | < 2.29 | [patch](https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c) | [hack.lu CTF 2015-bookstore](https://github.com/ctfs/write-ups-2015/tree/master/hack-lu-ctf-2015/exploiting/bookstore), [Nuit du Hack 2016-night-deamonic-heap](https://github.com/ctfs/write-ups-2016/tree/master/nuitduhack-quals-2016/exploit-me/night-deamonic-heap-400) |
| [overlapping_chunks_2.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.23/overlapping_chunks_2.c) | <a href="https://wargames.ret2.systems/level/how2heap_overlapping_chunks_2_2.23" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对使用中 chunk 大小的覆盖,使新分配与现有 chunk 重叠。  | < 2.29|[patch](https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c) | | |
| [mmap_overlapping_chunks.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/mmap_overlapping_chunks.c) | |  利用使用中的 mmap chunk,使新分配与当前的 mmap chunk 重叠。 | 最新 | | |
| [house_of_force.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.27/house_of_force.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_force_2.27" title="Debug Technique In Browser">:arrow_forward:</a> | 利用 Top Chunk(Wilderness)的头部信息,使 malloc 返回一个几乎任意的指针。 | < 2.29 | [patch](https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=30a17d8c95fbfb15c52d1115803b63aaa73a285c) | [Boston Key Party 2016-cookbook](https://github.com/ctfs/write-ups-2016/tree/master/boston-key-party-2016/pwn/cookbook-6), [BCTF 2016-bcloud](https://github.com/ctfs/write-ups-2016/tree/master/bctf-2016/exploit/bcloud-200) |
| [unsorted_bin_into_stack.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.27/unsorted_bin_into_stack.c) | <a href="https://wargames.ret2.systems/level/how2heap_unsorted_bin_into_stack_2.23" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对 unsorted bin 空闲链表上已释放 chunk 的覆盖,返回一个几乎任意的指针。  | < 2.29 | [patch](https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c)| | |
| [unsorted_bin_attack.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.27/unsorted_bin_attack.c) | <a href="https://wargames.ret2.systems/level/how2heap_unsorted_bin_attack_2.27" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对 unsorted bin 空闲链表上已释放 chunk 的覆盖,向任意地址写入一个大数值。  | < 2.29 | [patch](https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c) | [0ctf 2016-zerostorage](https://github.com/ctfs/write-ups-2016/tree/master/0ctf-2016/exploit/zerostorage-6) |
| [large_bin_attack.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/large_bin_attack.c) | <a href="https://wargames.ret2.systems/level/how2heap_large_bin_attack_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对 large bin 空闲链表上已释放 chunk 的覆盖,向任意地址写入一个大数值。  | < 2.42 | [patch](https://patchwork.sourceware.org/project/glibc/patch/[email protected]/) | [0ctf 2018-heapstorm2](https://dangokyo.me/2018/04/07/0ctf-2018-pwn-heapstorm2-write-up/) |
| [house_of_einherjar.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/house_of_einherjar.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_einherjar_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 利用单个 null 字节溢出,欺骗 malloc 返回一个受控指针。  | 最新 | | [Seccon 2016-tinypad](https://gist.github.com/hhc0null/4424a2a19a60c7f44e543e32190aaabf) |
| [house_of_water.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.36/house_of_water.c) | | 利用 UAF 或 double free,以无需泄露的方式控制 t-cache 元数据,并实现一种无需泄露即可将 libc 链入 t-cache 的方法。 | 最新 | | [37c3 Potluck - Tamagoyaki](https://github.com/UDPctf/CTF-challenges/tree/main/Potluck-CTF-2023/Tamagoyaki)|
| [sysmalloc_int_free.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.39/sysmalloc_int_free.c) | | 演示如何使用 malloc (sysmalloc  `_int_free()` ) 释放几乎任意大小的 Top Chunk(Wilderness) | 最新 | | |
| [house_of_orange.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.23/house_of_orange.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_orange_2.23" title="Debug Technique In Browser">:arrow_forward:</a> | 利用 Top Chunk(Wilderness)实现任意代码执行。  | < 2.26 | [patch](https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=stdlib/abort.c;h=117a507ff88d862445551f2c07abb6e45a716b75;hp=19882f3e3dc1ab830431506329c94dcf1d7cc252;hb=91e7cf982d0104f0e71770f5ae8e3faf352dea9f;hpb=0c25125780083cbba22ed627756548efe282d1a0) | [Hitcon 2016 houseoforange](https://github.com/ctfs/write-ups-2016/tree/master/hitcon-ctf-2016/pwn/house-of-orange-500) |
| [house_of_tangerine.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.39/house_of_tangerine.c) |  | 通过滥用 tcache 空闲链表,利用 Top Chunk(Wilderness)欺骗 malloc 返回一个完全任意的指针。 | >= 2.26 |  | [PicoCTF 2024- high frequency troubles](https://play.picoctf.org/practice/challenge/441?category=6&page=1&search=high%20frequency%20troubles) |
| [house_of_roman.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.23/house_of_roman.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_roman_2.23" title="Debug Technique In Browser">:arrow_forward:</a> | 一种无需泄露的技术,通过伪造 fastbins、unsorted\_bin attack 和相对覆盖实现远程代码执行。 |< 2.29 |[patch](https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c) || |
| [tcache_poisoning.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/tcache_poisoning.c) | <a href="https://wargames.ret2.systems/level/how2heap_tcache_poisoning_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 通过滥用 tcache 空闲链表,欺骗 malloc 返回一个完全任意的指针。(在 2.32 及之后需要堆泄露) | > 2.25  | [patch](https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=a1a486d70ebcc47a686ff5846875eacad0940e41) | | |
| [tcache_house_of_spirit.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/tcache_house_of_spirit.c) | <a href="https://wargames.ret2.systems/level/how2heap_tcache_house_of_spirit_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 释放一个伪造的 chunk,使 malloc 返回一个几乎任意的指针。 | > 2.25 | | |
| [house_of_botcake.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/house_of_botcake.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_botcake_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 绕过 tcache 的 double free 限制。让 `tcache_dup` 再次伟大。 | > 2.25 | | |
| [tcache_stashing_unlink_attack.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/tcache_stashing_unlink_attack.c) | <a href="https://wargames.ret2.systems/level/how2heap_tcache_stashing_unlink_attack_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对 small bin 空闲链表上已释放 chunk 的覆盖,借助 calloc 欺骗 malloc 返回一个任意指针,并向任意地址写入一个大数值。 | > 2.25 | | [Hitcon 2019 one punch man](https://github.com/xmzyshypnc/xz_files/tree/master/hitcon2019_one_punch_man) |
| [fastbin_reverse_into_tcache.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/fastbin_reverse_into_tcache.c) | <a href="https://wargames.ret2.systems/level/how2heap_fastbin_reverse_into_tcache_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 利用对 fastbin 中已释放 chunk 的覆盖,向任意地址写入一个大数值。 | 2.26 - 2.42 | [patch](https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=malloc/malloc.c;h=fa854fc4b8f75b09902ea7ed1180487beb6e4683;hp=7811152d9d9eba3e0f0a3416d9944cc142caaafe;hb=bf1015fb2d7e4057925481960626533f8571a2fb;hpb=e3062b06c5767f672baf9574c4d7cbebf7d0ee6e) | | |
| [house_of_mind_fastbin.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/house_of_mind_fastbin.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_mind_fastbin_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 结合 arena 处理,利用单字节覆盖向任意地址写入一个大数值(堆指针)。 | < 2.43 | [patch](https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=malloc/malloc.c;h=fa854fc4b8f75b09902ea7ed1180487beb6e4683;hp=7811152d9d9eba3e0f0a3416d9944cc142caaafe;hb=bf1015fb2d7e4057925481960626533f8571a2fb;hpb=e3062b06c5767f672baf9574c4d7cbebf7d0ee6e) | | |
| [house_of_storm.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.27/house_of_storm.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_storm_2.27" title="Debug Technique In Browser">:arrow_forward:</a> | 利用 large bin 和 unsorted bin chunk 上的 use-after-free,使 malloc 返回任意 chunk。 | < 2.29 | | |
| [house_of_gods.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.24/house_of_gods.c) | <a href="https://wargames.ret2.systems/level/how2heap_house_of_gods_2.24" title="Debug Technique In Browser">:arrow_forward:</a> | 一种在 8 次分配内劫持线程 arena 的技术。 | < 2.27 | | |
| [decrypt_safe_linking.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.35/decrypt_safe_linking.c) | <a href="https://wargames.ret2.systems/level/how2heap_decrypt_safe_linking_2.34" title="Debug Technique In Browser">:arrow_forward:</a> | 解密链表中的毒化值,以恢复真实的指针。 | >= 2.32 | | |
| [safe_link_double_protect.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.36/safe_link_double_protect.c) | | 通过两次保护指针,实现对 PROTECT_PTR 的无泄露绕过,从而允许在 t-cache 中链接任意指针。 | >= 2.32 | | [37c3 Potluck - Tamagoyaki](https://github.com/UDPctf/CTF-challenges/tree/main/Potluck-CTF-2023/Tamagoyaki)|
| [tcache_dup.c](https://github.com/shellphish/how2heap/blob/master/obsolete/glibc_2.27/tcache_dup.c)(已废弃) | |  通过滥用 tcache 空闲链表,欺骗 malloc 返回一个已分配的堆指针。 | 2.26 - 2.28 | [patch](https://sourceware.org/git/?p=glibc.git;a=commit;h=bcdaad21d4635931d1bd3b54a7894276925d081d) | | |
| [tcache_metadata_poisoning.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.27/tcache_metadata_poisoning.c) | | 通过操纵 tcache 元数据结构体,诱使 tcache 提供任意指针。 | >= 2.26 | | |
| [house_of_io.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.31/house_of_io.c) | | 通过在已释放的 tcache chunk 中利用 UAF 操纵 tcache 管理结构体,欺骗 malloc 返回指向任意内存的指针。 | 2.31 - 2.33 | | |
| [tcache_relative_write.c](https://github.com/shellphish/how2heap/blob/master/glibc_2.41/tcache_relative_write.c) | | 通过越界写入 tcache 元数据,在堆中写入任意十进制值和 chunk 指针。 | 2.30-2.41 | [patch](https://sourceware.org/git/?p=glibc.git;a=commit;h=cbfd7988107b27b9ff1d0b57fa2c8f13a932e508) | | |
| [tcache_metadata_hijacking](https://github.com/shellphish/how2heap/blob/master/glibc_2.42/tcache_metadata_hijacking.c) | | 通过溢出到 tcache 元数据实现任意分配。 | >= 2.42 | | |

GnuLibc 在不断开发中,上述多种技术已导致 malloc/free 逻辑中引入一致性检查。
因此,这些检查经常会使某些技术失效,并需要调整以绕过它们(如果可能的话)。
我们通过为每个需要调整的 Glibc 版本保留同一技术的多个版本来解决这个问题。
目录结构为 `glibc_<version>/technique.c`。

有好例子吗?
把它添加到这里!
尝试将整个技术内联到单个 `.c` 文件中——这样学起来容易得多。

# 快速入门

## 快速设置

- 确保你已安装以下软件包/工具:`patchelf zstd wget`(当然还需要 `build-essential` 或类似的编译器工具包、`make` 等)。
- 此外,`/usr/bin/python` 必须是你 `python` 二进制文件的路径或指向该路径(例如 `/usr/bin/python3`)。```shell
git clone https://github.com/shellphish/how2heap
cd how2heap
make clean base
./malloc_playground
```
注意,这会将二进制文件与你的系统 libc 链接。如果你想使用其他 libc 版本,请参阅 `Complete Setup`。

## 完整设置

如果你尝试对在宿主机上编译的二进制文件进行 `LD_PRELOAD` libc,将会遇到符号版本问题(参见[这个](https://github.com/shellphish/how2heap/issues/169))。
我们有两种方法可以绕过它。

### 方法 1:链接到较旧的 libc
这个方法告诉链接器将目标二进制文件与目标 libc 链接。```shell
git clone https://github.com/shellphish/how2heap
cd how2heap
H2H_USE_SYSTEM_LIBC=N make v2.23
```
这将把所有二进制文件与相应的 libc 版本链接起来。更好的是,它自带调试符号。现在,你可以在宿主机上使用任意 libc 版本进行实验。
在此示例中,它将编译所有 glibc-2.23 二进制文件,并将它们与 libc-2.23 链接。你可以更改该数字,以尝试其他 libc 版本。

### 方法 2:使用 docker
该方法使用基于 Docker 的方式,在旧版 ubuntu 容器内编译二进制文件,从而使其能在目标 libc 版本下运行。```shell
git clone https://github.com/shellphish/how2heap
cd how2heap

# the next command will prepare the target binary so it runs with
# the expected libc version
make base
./glibc_run.sh 2.30 ./malloc_playground -d -p

# now you can play with the binary with glibc-2.30
# and even debug it with the correct symbols
readelf -d -W malloc_playground | grep RUNPATH # or use checksec
readelf -l -W malloc_playground | grep interpreter
gdb -q -ex "start" ./malloc_playground
```
# Heap Exploitation Tools

这里有一些流传的堆利用工具。

## Malloc Playground

所给出的 `malloc_playground.c` 文件是一个程序的源代码,该程序会提示用户输入命令,以交互方式分配和释放内存。

## Pwngdb

在 gdb 中检查 glibc 堆:https://github.com/scwuaptx/Pwngdb

## pwndbg

一个以利用为中心的 gdb 插件,提供查看/篡改 glibc 堆的能力:https://github.com/pwndbg/pwndbg

## gef

另一个优秀的 gdb 插件,提供检查 glibc 堆的能力:https://github.com/hugsy/gef

## heap-viewer

在 IDA Pro 中检查 glibc 堆:https://github.com/danigargu/heap-viewer

## heaptrace

通过用符号替换地址来帮助你可视化堆操作:https://github.com/Arinerron/heaptrace

# 其他资源

一些不错的堆利用资源,大致按发布时间的倒序排列如下:

## 有用的堆利用教程
- GLIBC 堆利用技术概述 (https://0x434b.dev/overview-of-glibc-heap-exploitation-techniques/) <!-- 2022 -->
- glibc 深入教程 (https://heap-exploitation.dhavalkapil.com/) - 书籍和漏洞利用示例 <!-- 2022 -->
- 适用于 glibc-2.31 的堆利用技术 (https://github.com/StarCross-Tech/heap_exploit_2.31) <!-- 2020 -->
- Linux 用户态堆的无痛入门 (https://sensepost.com/blog/2017/painless-intro-to-the-linux-userland-heap/) <!-- 2017 -->
- ptmalloc 爱好者杂志,一组与 ptmalloc 元数据攻击相关的资源和示例 (http://tukan.farm/2016/07/26/ptmalloc-fanzine/) <!-- 2016 -->
- Glibc 冒险:被遗忘的块 (https://github.com/bash-c/slides/blob/master/pwn_heap/Glibc%20Adventures:%20The%20forgotten%20chunks.pdf) - 高级堆利用 <!-- 2015 -->

## 历史堆利用(历史)
- Pseudomonarchia jemallocum (http://www.phrack.org/issues/68/10.html) <!-- 2012 -->
- The House Of Lore: Reloaded (http://phrack.org/issues/67/8.html) <!-- 2010 -->
- Malloc Des-Maleficarum (http://phrack.org/issues/66/10.html) - 一些 malloc 利用技术 <!-- 2009 -->
- 又一种 free() 利用技术 (http://phrack.org/issues/66/6.html) <!-- 2009 -->
- 使用 set_head 对抗 wilderness (http://phrack.org/issues/64/9.html) <!-- 2007 -->
- 通过破坏堆来理解堆 (https://www.blackhat.com/presentations/bh-usa-07/Ferguson/Whitepaper/bh-usa-07-ferguson-WP.pdf) - 解释堆的实现和一些漏洞利用 <!-- 2007 -->
- OS X 堆利用技术 (http://phrack.org/issues/63/5.html) <!-- 2005 -->
- The Malloc Maleficarum (http://seclists.org/bugtraq/2005/Oct/118) <!-- 2005 -->
- 利用 Wilderness (http://seclists.org/vuln-dev/2004/Feb/25) <!-- 2004 -->
- 高级 Doug lea malloc 漏洞利用技术 (http://phrack.org/issues/61/6.html) <!-- 2003 -->

# 加固
glibc 中内置了一些“加固”措施,比如 `export MALLOC_CHECK_=1`(启用一些检查)、`export MALLOC_PERTURB_=1`(数据会被覆盖)、`export MALLOC_MMAP_THRESHOLD_=1`(始终使用 mmap())……

更多信息:[mcheck()](http://www.gnu.org/software/libc/manual/html_node/Heap-Consistency-Checking.html)、[mallopt()](http://www.gnu.org/software/libc/manual/html_node/Malloc-Tunable-Parameters.html)。

还有一些跟踪支持,如 [mtrace()](http://manpages.ubuntu.com/mtrace)、[malloc_stats()](http://manpages.ubuntu.com/malloc_stats)、[malloc_info()](http://manpages.ubuntu.com/malloc_info)、[memusage](http://manpages.ubuntu.com/memusage),以及该系列中的其他函数。
下载工具