Thursday, 19 September 2019

Linux Heap TCache House of Spirit

In this paper, I introduce the reader to a heap metadata corruption against the latest version of the glibc allocator, ptmalloc. In the TCache House of Spirit, an attacker passes a pointer to a fake chunk header to the free API. This chunk can be of almost arbitrary size. The allocator will subsequently insert this fake chunk into a tcache freelist. The next malloc of the appropriate size will return the fake chunk which may overlap data that may be of benefit to the attacker.

Linux Heap TCache House of Spirit.PDF

Exploiting the Lorex 2K Indoor Wifi at Pwn2Own Ireland

Introduction In October InfoSect participated in Pwn2Own Ireland 2024 and successfully exploited the Sonos Era 300 smart speaker and Lor...