Skip to content

Latest commit

 

History

History
3 lines (2 loc) · 346 Bytes

README.md

File metadata and controls

3 lines (2 loc) · 346 Bytes

Heap Storm II - 0ctf quals 2018

Corrupt large bin chunk's bk_nextsize, trigger code that put unsorted bin chunk into large bin list. Crafting their size relationship to achieve arbitrary shoot. Putting a size and bk pointer on the uncontrolled area, then unsorted bin attack wouldn't crash the program when there is a valid bk pointer.