zoukankan      html  css  js  c++  java
  • how2heap libc2.31学习

      今天是四月十九,想在五月份之前把how2heap中的高版本(2.31)的例子过一遍。所以这个系列目前还是在更新中。如果比较简单就几句话带过了,遇到难一点的会写的详细一点。

    fastbin_dup

    源代码:

     1 #include <stdio.h>
     2 #include <stdlib.h>
     3 #include <assert.h>
     4 
     5 int main()
     6 {
     7     setbuf(stdout, NULL);
     8 
     9     printf("This file demonstrates a simple double-free attack with fastbins.
    ");
    10 
    11     printf("Fill up tcache first.
    ");
    12     void *ptrs[8];
    13     for (int i=0; i<8; i++) {
    14         ptrs[i] = malloc(8);
    15     }
    16     for (int i=0; i<7; i++) {
    17         free(ptrs[i]);
    18     }
    19 
    20     printf("Allocating 3 buffers.
    ");
    21     int *a = calloc(1, 8);
    22     int *b = calloc(1, 8);
    23     int *c = calloc(1, 8);
    24 
    25     printf("1st calloc(1, 8): %p
    ", a);
    26     printf("2nd calloc(1, 8): %p
    ", b);
    27     printf("3rd calloc(1, 8): %p
    ", c);
    28 
    29     printf("Freeing the first one...
    ");
    30     free(a);
    31 
    32     printf("If we free %p again, things will crash because %p is at the top of the free list.
    ", a, a);
    33     // free(a);
    34 
    35     printf("So, instead, we'll free %p.
    ", b);
    36     free(b);
    37 
    38     printf("Now, we can free %p again, since it's not the head of the free list.
    ", a);
    39     free(a);
    40 
    41     printf("Now the free list has [ %p, %p, %p ]. If we malloc 3 times, we'll get %p twice!
    ", a, b, a, a);
    42     a = calloc(1, 8);
    43     b = calloc(1, 8);
    44     c = calloc(1, 8);
    45     printf("1st calloc(1, 8): %p
    ", a);
    46     printf("2nd calloc(1, 8): %p
    ", b);
    47     printf("3rd calloc(1, 8): %p
    ", c);
    48 
    49     assert(a == c);
    50 }
    View Code

    总结:

      1.使用calloc申请chunk,并不会从tcache中拿chunk。

      2.如果存在uaf漏洞,可以先将tcache填充满,再利用free(a),free(b),free(a)的操作实现double free,实现任意写。

  • 相关阅读:
    子页面与父页面相互调用函数、元素、变量
    springboot项目多数据源及其事务
    mybatis逆向工程
    PageHelper 分页插件
    spring boot 在eclipse中打war包,及jar包
    Spring 定时任务之 @Scheduled cron表达式
    发送邮件
    spring+springmvc+hibernate 框架搭建
    MySQL驱动和数据库字符集设置不搭配
    Oracle与MySQL区别
  • 原文地址:https://www.cnblogs.com/bhxdn/p/14676214.html
Copyright © 2011-2022 走看看