Understanding C Pointer Magic Arithmetic | Ep. 07 @LiveOverflow
Understanding C Pointer Magic Arithmetic | Ep. 07  @LiveOverflow
Uploaded July 2021 | Updated September 2026, 2 weeks ago
We debug the line that causes the heap overflow. And it's a great opportunity to understand pointers in C.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-sudoedit/understanding-the-vulnerability
Join the Hextree Discord: discord.gg/xgQpCQCpvy

The full playlist: youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx

Grab the files: github.com/LiveOverflow/pwnedit

The original disclosure: blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit

Episode 07:

CHAPTERS
00:00 - Intro & Motivation
00:46 - Create Debug Build
01:02 - The Crashing Location
01:43 - Scary Pointer Magic
02:10 - *to++ = *from
02:56 - Explaining: from++
04:03 - Explaining: *from
04:56 - Explaining: to++
05:23 - Explaining: *to = *from
05:54 - The Copy While Loop
06:26 - Explaining: from[0] vs *from
07:14 - The Bug!
08:35 - Wrong Allocation Size Calculated
09:30 - Unescape Logic
10:15 - Why though?

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#BufferOverflow #BinaryExploitation #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Understanding C Pointer Magic Arithmetic | Ep. 07
LiveOverflow |

Understanding C Pointer Magic Arithmetic | Ep. 07

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER