Developing GDB Extension for Heap Exploitation | Ep. 12 @LiveOverflow
Developing GDB Extension for Heap Exploitation | Ep. 12  @LiveOverflow
Uploaded November 2021 | Updated September 2026, 2 weeks ago
We aren't getting anywhere... So we write a new tool to analyse the heap objects located after our overflowing buffer.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-sudoedit/failing-to-exploit-sudo
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Complete Playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
Grab the files: github.com/LiveOverflow/pwnedit (sorry, repo is a bit behind the videos)

gef for gdb: github.com/hugsy/gef

Episode 12:

CHAPTERS
00:00 - Intro
00:12 - How to Find Controllable Heap Allocations?
00:50 - Tracing free()!
01:21 - Finding Recognizable Strings on the Heap
01:58 - More Environment Variables
03:26 - fengshui2.py Script Changes
04:19 - Wrong Rabbit Hole...
05:20 - Some Other Research Attempts
06:47 - (gdb) gef Extension - Analyse the Heap Objects
09:03 - Heap Tracing Results
09:51 - Developing fengshui3.py
10:52 - First Peak at Script Results

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#BufferOverflow #LinuxSecurity #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Developing GDB Extension for Heap Exploitation | Ep. 12Hacking Google Cloud?The First Exploit  - Pwn2Own Documentary (Part 2)Why Pick sudo as Research Target? | Ep. 01Can AI Create a Minecraft Hack?Design Flaw in Security Product - ALLES! CTF 2021Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228Defusing a Bomb at Google London HQ - Having a Blast Google CTF Finals 2019 (hardware)Do you know this common Go vulnerability?Does Hacking Require Programming Skills?Security-driven Rapid Release - Pwn2Own Documentary (Part 4)How The RIDL CPU Vulnerability Was Found
LiveOverflow |

Developing GDB Extension for Heap Exploitation | Ep. 12

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER