video thumbnail 11:58
Format String Exploit and overwrite the Global Offset Table - bin 0x13

2016-08-16

[public] 59.0K views, 1.38K likes, 7.00 dislikes audio only

channel thumbLiveOverflow

In this episode we combine the last two videos. Format String + overwriting an entry of the Global Offset Table to solve format4 from exploit.education

format4: https://exploit.education/protostar/format-four/

-=[ 🔴 Stuff I use ]=-

→ Microphone:* https://geni.us/ntg3b

→ Graphics tablet:* https://geni.us/wacom-intuos

→ Camera#1 for streaming:* https://geni.us/sony-camera

→ Lens for streaming:* https://geni.us/sony-lense

→ Connect Camera#1 to PC:* https://geni.us/cam-link

→ Keyboard:* https://geni.us/mech-keyboard

→ Old Microphone:* https://geni.us/mic-at2020usb

US Store Front:* https://www.amazon.com/shop/liveoverflow

-=[ ❤️ Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ 🐕 Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/

-=[ 📄 P.S. ]=-

All links with "*" are affiliate links.

LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#BinaryExploitation #FormatString


A simple Format String exploit example - bin 0x11 by LiveOverflow
/youtube/video/0WvrSfcdq1I
Global Offset Table (GOT) and Procedure Linkage Table (PLT) - bin 0x12 by LiveOverflow
/youtube/video/kUk5pw4w0h4
set two break points
/youtube/video/t1LH9D5cuK4?t=183.07001
print the first four values from the stack
/youtube/video/t1LH9D5cuK4?t=274.84
replace our characters with the address of the global offset table
/youtube/video/t1LH9D5cuK4?t=326.29001
execute the printf
/youtube/video/t1LH9D5cuK4?t=364.009