Linux Heap Exploitation Intro Series – (BONUS) printf might be leaking!
ID: d78f9786-742b-54db-908f-cf9c977584a8
STIX ID: report--d78f9786-742b-54db-908f-cf9c977584a8
Feed Name: SensePost Blog
Threat Score
This blog post analyzes a heap exploitation technique where vfprintf-family functions (printf/puts) allocate a persistent ~0x410 heap chunk in glibc 2.23/2.24, which can be abused with a double-free primitive to overwrite adjacent chunk metadata and achieve code execution; the author provides PoC code, gdb/pwndbg guidance, and details on compilation and shellcode usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
