Uploaded December 2022 | Updated September 2026, 2 weeks ago
Everybody told me the cat coordinate exploit/leak was already known. However this does not seem to be true, I tested it by logging packets.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-minecraft/researching-minecraft-hacks
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Cat Coordinate Exploit 1.19.2: youtube.com/watch?v=Gi2PPBCEHuM
Watch the full playlist: youtube.com/playlist?list=PLhixgUqwRTjwvBI-hmbZ2rpkAl4lutnJG
After I made the video I realized I should have showcased this project:
Minecraft Packet Monitor: github.com/Heath123/pakkit
Community Showcase:
TudbuT - youtu.be/ipTqARwCmEE
7H3, MonkeySaint
Episode 19:
CHAPTERS
00:00 - Intro
00:38 - 2b2t Tamed Animal Coordinate Leak
01:20 - Experiment Setup
02:32 - Packet Logging Experiment
04:55 - Experiment Conclusion
06:15 - Fixing the Coordinate Leak
06:58 - Community Showcase
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GameHacking #Minecraft #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Everybody told me the cat coordinate exploit/leak was already known. However this does not seem to be true, I tested it by logging packets.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-minecraft/researching-minecraft-hacks
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Cat Coordinate Exploit 1.19.2: youtube.com/watch?v=Gi2PPBCEHuM
Watch the full playlist: youtube.com/playlist?list=PLhixgUqwRTjwvBI-hmbZ2rpkAl4lutnJG
After I made the video I realized I should have showcased this project:
Minecraft Packet Monitor: github.com/Heath123/pakkit
Community Showcase:
TudbuT - youtu.be/ipTqARwCmEE
7H3, MonkeySaint
Episode 19:
CHAPTERS
00:00 - Intro
00:38 - 2b2t Tamed Animal Coordinate Leak
01:20 - Experiment Setup
02:32 - Packet Logging Experiment
04:55 - Experiment Conclusion
06:15 - Fixing the Coordinate Leak
06:58 - Community Showcase
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GameHacking #Minecraft #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
![How SUDO on Linux was HACKED! // CVE-2021-3156
The most comprehensive video covering the sudo vulnerability CVE-2021-3156 Baron Samedit. I spent two weeks on rediscovering, analysing and exploitation of the sudoedit heap overflow. We will talk about fuzzing, code review, exploit strategies, heap feng shui and developing the exploit.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-sudoedit/sudoedit-introduction
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
Article: https://liveoverflow.com/critical-sudo-vulnerability-walkthrough-cve-2021-3156/
Binary Exploitation Playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN
PwnFunctions Binary Exploitation Playlist: https://www.youtube.com/playlist?list=PLI_rLWXMqpSkAYfar0HRA7lykydwmRY_2
Full CVE-2021-3156 Advisory: https://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html
Qualys Blog: https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit
milek7s blog on fuzzing sudo: https://milek7.pl/howlongsudofuzz/
CHAPTERS
00:00 - Intro and Motivation
01:33 - afl: Fuzzing argv[]
03:22 - afl: sudo vs. sudoedit
04:27 - afl: Fuzzing setuid Process
06:49 - Fuzzing Conclusion
07:11 - Code Review: Identify Risky Code Through Isolation
09:39 - Code Review: Bypass Safe Conditions
11:15 - Exploit Strategy: Modern Mitigations
12:25 - The service_user Object Overwrite Technique
13:48 - Heap Feng Shui via Environment Variables
14:57 - Bruteforce Script to Find Exploitable Conditions
15:39 - Find and Analyse Useful Crashes
16:31 - Exploitability Analysis Conclusion
17:13 - Qualys Researchers Knew nss From Stack Clash
17:47 - Sudoedit Exploitable on macOs?
18:32 - Research Conclusion
19:27 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BufferOverflow #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. How SUDO on Linux was HACKED! // CVE-2021-3156](https://i.ytimg.com/vi/TLa2VqcGGEQ/mqdefault.jpg)









