Uploaded August 2020 | Updated September 2026, 2 weeks ago
The last day of my trip to the Google CTF Finals 2019 in London. We try the Bomb challenge again, talk to the authors of the RIDL and Fractalization challenges, and see the final solutions, awards, and winners.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-general-education/conference-and-ctf-vlogs
Join the Hextree Discord: discord.gg/xgQpCQCpvy
"advertisement" because Google paid for flight and hotel.
Google CTF Finals Challenges: gctf-2019.appspot.com
Challenge Sources (and solutions): github.com/google/google-ctf/tree/master/2019/finals
CHAPTERS
00:00 - Final morning of the Google CTF finals
01:01 - Second attempt at the Bomb challenge
01:34 - How RIDL became a CTF challenge
02:51 - Breaking the Fractalization RSA challenge
08:42 - Swag puzzle and Bomb challenge results
12:23 - Challenge solution presentations
14:39 - Awards ceremony and winners
16:46 - Recapping the final competition day
19:28 - Public RIDL exploit and the trip home
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#CTF #Cryptography #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
The last day of my trip to the Google CTF Finals 2019 in London. We try the Bomb challenge again, talk to the authors of the RIDL and Fractalization challenges, and see the final solutions, awards, and winners.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-general-education/conference-and-ctf-vlogs
Join the Hextree Discord: discord.gg/xgQpCQCpvy
"advertisement" because Google paid for flight and hotel.
Google CTF Finals Challenges: gctf-2019.appspot.com
Challenge Sources (and solutions): github.com/google/google-ctf/tree/master/2019/finals
CHAPTERS
00:00 - Final morning of the Google CTF finals
01:01 - Second attempt at the Bomb challenge
01:34 - How RIDL became a CTF challenge
02:51 - Breaking the Fractalization RSA challenge
08:42 - Swag puzzle and Bomb challenge results
12:23 - Challenge solution presentations
14:39 - Awards ceremony and winners
16:46 - Recapping the final competition day
19:28 - Public RIDL exploit and the trip home
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#CTF #Cryptography #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.

![How SUDO on Linux was HACKED! // CVE-2021-3156
The most comprehensive video covering the sudo vulnerability CVE-2021-3156 Baron Samedit. I spent two weeks on rediscovering, analysing and exploitation of the sudoedit heap overflow. We will talk about fuzzing, code review, exploit strategies, heap feng shui and developing the exploit.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-sudoedit/sudoedit-introduction
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
Article: https://liveoverflow.com/critical-sudo-vulnerability-walkthrough-cve-2021-3156/
Binary Exploitation Playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN
PwnFunctions Binary Exploitation Playlist: https://www.youtube.com/playlist?list=PLI_rLWXMqpSkAYfar0HRA7lykydwmRY_2
Full CVE-2021-3156 Advisory: https://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html
Qualys Blog: https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit
milek7s blog on fuzzing sudo: https://milek7.pl/howlongsudofuzz/
CHAPTERS
00:00 - Intro and Motivation
01:33 - afl: Fuzzing argv[]
03:22 - afl: sudo vs. sudoedit
04:27 - afl: Fuzzing setuid Process
06:49 - Fuzzing Conclusion
07:11 - Code Review: Identify Risky Code Through Isolation
09:39 - Code Review: Bypass Safe Conditions
11:15 - Exploit Strategy: Modern Mitigations
12:25 - The service_user Object Overwrite Technique
13:48 - Heap Feng Shui via Environment Variables
14:57 - Bruteforce Script to Find Exploitable Conditions
15:39 - Find and Analyse Useful Crashes
16:31 - Exploitability Analysis Conclusion
17:13 - Qualys Researchers Knew nss From Stack Clash
17:47 - Sudoedit Exploitable on macOs?
18:32 - Research Conclusion
19:27 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BufferOverflow #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. How SUDO on Linux was HACKED! // CVE-2021-3156](https://i.ytimg.com/vi/TLa2VqcGGEQ/mqdefault.jpg)








