logo

CUCTF 2020 Dr. Xorisaurus Heap Writeup (glibc 2.32 UAF)

ID: 56b92fc0-3ebd-5a1f-9555-eff9a08c46cc

STIX ID: report--56b92fc0-3ebd-5a1f-9555-eff9a08c46cc

Feed Name: Will's Root

Date Published: 2020-10-04

Date Updated: 2026-04-19

Author: Unknown

...
...

This writeup describes a CTF challenge exploit against glibc 2.32 heap protections, explaining how safe-linking obfuscation, scanf-induced large allocations, malloc_consolidate behavior, and an 8-byte UAF are abused to perform tcache poisoning and ultimately overwrite __free_hook to achieve a shell. The author details the challenge features, the leak technique using largebin consolidation, pointer deobfuscation math, and how the final payload changes __free_hook to system; it is an educational exploit walkthrough rather than a report of active malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.