House of Emma
Posted on 2024-10-12
Defeat the pointer guard and hijack execution flow.
High level GLIBC I/O operation exploit: Largebin Attack + FSOP
ORW ROP chain with magic gadgets to pwn a Sandbox
Large Bin Attack is the future. Hijack bk_nextsize pointer to exploit.
There is no excerpt because this is a protected post.
Safe-linking is a mitigation but also a weapon in some cases.
The authors of glibc try to stop us leveraging the unlink macro, but