Uploaded November 2021 | Updated September 2026, 2 weeks ago
We aren't getting anywhere... So we write a new tool to analyse the heap objects located after our overflowing buffer.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-sudoedit/failing-to-exploit-sudo
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Complete Playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
Grab the files: github.com/LiveOverflow/pwnedit (sorry, repo is a bit behind the videos)
gef for gdb: github.com/hugsy/gef
Episode 12:
CHAPTERS
00:00 - Intro
00:12 - How to Find Controllable Heap Allocations?
00:50 - Tracing free()!
01:21 - Finding Recognizable Strings on the Heap
01:58 - More Environment Variables
03:26 - fengshui2.py Script Changes
04:19 - Wrong Rabbit Hole...
05:20 - Some Other Research Attempts
06:47 - (gdb) gef Extension - Analyse the Heap Objects
09:03 - Heap Tracing Results
09:51 - Developing fengshui3.py
10:52 - First Peak at Script Results
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#BufferOverflow #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
We aren't getting anywhere... So we write a new tool to analyse the heap objects located after our overflowing buffer.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-sudoedit/failing-to-exploit-sudo
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Complete Playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
Grab the files: github.com/LiveOverflow/pwnedit (sorry, repo is a bit behind the videos)
gef for gdb: github.com/hugsy/gef
Episode 12:
CHAPTERS
00:00 - Intro
00:12 - How to Find Controllable Heap Allocations?
00:50 - Tracing free()!
01:21 - Finding Recognizable Strings on the Heap
01:58 - More Environment Variables
03:26 - fengshui2.py Script Changes
04:19 - Wrong Rabbit Hole...
05:20 - Some Other Research Attempts
06:47 - (gdb) gef Extension - Analyse the Heap Objects
09:03 - Heap Tracing Results
09:51 - Developing fengshui3.py
10:52 - First Peak at Script Results
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#BufferOverflow #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.


![Why Pick sudo as Research Target? | Ep. 01
A serious sudo vulnerability had just been announced, but how do researchers find bugs like it? This first episode explains why sudo is an interesting target, prepares a reproducible research environment, and begins an AFL fuzzing strategy that immediately runs into practical problems.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-sudoedit/sudoedit-introduction
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
RESOURCES
Text version: https://liveoverflow.com/why-pick-sudo-research-target-part-1/
Episode files: https://github.com/LiveOverflow/pwnedit/tree/main/episode01
Full playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
CHAPTERS
00:00 - Intro
01:48 - Prepare the System
03:57 - How to Pick a Research Target?
05:57 - Choose the Strategy: Fuzzing
09:27 - Fuzzing argv[] With AFL
13:00 - Running Into the Next AFL Problem
14:51 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BinaryExploitation #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Why Pick sudo as Research Target? | Ep. 01](https://i.ytimg.com/vi/uj1FTiczJSE/mqdefault.jpg)







