30.07.2014 Views

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Arbitrary Free I<br />

• Assume you can overflow into a pointer<br />

returned from <strong>Heap</strong>Alloc called X<br />

– i.e. X = <strong>Heap</strong>Alloc(h<strong>Heap</strong>, 0, 4096);<br />

• Application will <strong>Heap</strong>Free X at some point<br />

• So…

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!