Tuesday, 24 September 2019

Linux Heap Fast Bin Poisoning part 2

In this paper, I introduce the reader to a heap metadata corruption against the current Linux Heap allocator, ptmalloc. The attack is performed via corrupting, or poisoning the fast bin such that malloc returns an arbitrary pointer. It relaxes the requirements in part 1 of this paper and can now return an arbitrary pointer. For this to happen, more heap grooming is required.

Linux Heap Fast Bin Poisoning part 2.PDF

Exploiting the Lorex 2K Indoor Wifi at Pwn2Own Ireland

Introduction In October InfoSect participated in Pwn2Own Ireland 2024 and successfully exploited the Sonos Era 300 smart speaker and Lor...