30.07.2014 Views

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

LFH bucket overflow VI<br />

LFH bucket overflow requirements:<br />

• Position overflow chunk before some LFH<br />

bucket<br />

• Find an appropriate X value<br />

• Craft or find an appropriate fake LFH<br />

context (Y)<br />

• Form a correct h<strong>Heap</strong> payload at <strong>the</strong><br />

location decided by Y<br />

• Reliably trigger R-allocation after overflow

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!