video thumbnail 10:44
Stack grooming and 100% reliable exploit for format0 - bin 0x25

2017-11-24

[public] 13.0K views, 451 likes, 4.00 dislikes audio only

Last week I thought this level couldn't be exploited. It turns out there is a way!

wcbowling's comment: https://www.reddit.com/r/LiveOverflow/comments/7dmrx8/playing_around_with_a_format_string_vulnerability/dq02kos/

asciinema: https://asciinema.org/a/148133

-=[ šŸ”“ Stuff I use ]=-

ā†’ Microphone:* https://geni.us/ntg3b

ā†’ Graphics tablet:* https://geni.us/wacom-intuos

ā†’ Camera#1 for streaming:* https://geni.us/sony-camera

ā†’ Lens for streaming:* https://geni.us/sony-lense

ā†’ Connect Camera#1 to PC:* https://geni.us/cam-link

ā†’ Keyboard:* https://geni.us/mech-keyboard

ā†’ Old Microphone:* https://geni.us/mic-at2020usb

US Store Front:* https://www.amazon.com/shop/liveoverflow

-=[ ā¤ļø Support ]=-

ā†’ per Video: https://www.patreon.com/join/liveoverflow

ā†’ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

ā†’ Twitter: https://twitter.com/LiveOverflow/

ā†’ Website: https://liveoverflow.com/

ā†’ Subreddit: https://www.reddit.com/r/LiveOverflow/

ā†’ Facebook: https://www.facebook.com/LiveOverflow/

-=[ šŸ“„ P.S. ]=-

All links with "*" are affiliate links.

LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#BinaryExploitation #FormatString


Playing around with a Format String vulnerability and ASLR. format0 - bin 0x24 by LiveOverflow
/youtube/video/CyazDp-Kkr0
write to the global offset table
/youtube/video/AahpiYxKR2c?t=132.66
increase or decrease the padding and 8 byte steps
/youtube/video/AahpiYxKR2c?t=389.97
groom the stick by adding or removing entries
/youtube/video/AahpiYxKR2c?t=459.35001
jump in between the bytes of the intended instruction
/youtube/video/AahpiYxKR2c?t=582.56
LiveOverflow just a wannabe hacker... making videos about various IT security topics and participating in hacking competitions. -=[ ā¤ļø Support me ]=- Patreon per Video: https://www.patreon.com/join/liveoverflow YouTube Membership per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ šŸ“„ Imprint ]=- Security Flag GmbH Celsiusstr. 72 12207 Berlin Germany
/youtube/channel/UClcE-kVhqyiHCcjYwcpfj9w
Iā€™m moving, no videos sorry 17,541 views
/youtube/video/9CS3q0uG1LI
Podcast by LiveOverflow
/youtube/video/nKR44fDM_uc