video thumbnail 8:40
Can We Find a Exploit Strategy?

2021-12-14

[public] 10.0K views, 1.41K likes, dislikes audio only

channel thumbLiveOverflow

We are still looking for an exploit strategy for the sudo heap overflow. In this episode we look at a few crashes and decide to look into one particular case more deeply.

Complete Playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx

Grab the files: https://github.com/LiveOverflow/pwnedit (sorry, repo is a bit behind the videos)

Homework libc source code: https://elixir.bootlin.com/glibc/glibc-2.31/source

Episode 13:

00:00 - Intro

00:36 - Recap of Episode 12

01:16 - Interpret Fuzzing Results | fengshui3

03:05 - Reproduction Script poc.py

04:16 - Heap Object Information not Useful

05:10 - Collect More Data on Crashes | fengshui4

05:32 - Looking at Crashes

06:35 - Intersting Crash in nss_lookup_function

07:00 - Homework

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Instagram: https://instagram.com/LiveOverflow/

→ Blog: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Developing GDB Extension for Heap Exploitation | Ep. 12 by LiveOverflow
/youtube/video/tzUrYsQRHfs
Intro
/youtube/video/Y8qljlUjEEM?t=0
Recap of Episode 12
/youtube/video/Y8qljlUjEEM?t=36
Interpret Fuzzing Results | fengshui3
/youtube/video/Y8qljlUjEEM?t=76
Reproduction Script poc.py
/youtube/video/Y8qljlUjEEM?t=185
Heap Object Information not Useful
/youtube/video/Y8qljlUjEEM?t=256
Collect More Data on Crashes | fengshui4
/youtube/video/Y8qljlUjEEM?t=310
Looking at Crashes
/youtube/video/Y8qljlUjEEM?t=332
Intersting Crash in nss_lookup_function
/youtube/video/Y8qljlUjEEM?t=395
Homework
/youtube/video/Y8qljlUjEEM?t=420
I’m moving, no videos sorry 17,541 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
Sudo Vulnerability Walkthrough by LiveOverflow
/youtube/video/TLa2VqcGGEQ