House of Banana
Posted on 2024-10-21
Hijack execution flow by abusing _rtld_global in ld.so
Binary exploitation categories.
High level GLIBC I/O operation exploit: Largebin Attack + FSOP
ORW ROP chain with magic gadgets to pwn a Sandbox
Large Bin Attack is the future. Hijack bk_nextsize pointer to exploit.
Safe-linking is a mitigation but also a weapon in some cases.
There are a lot shellcode loaders for Windows but rarely for Linux.