30.07.2014 Views

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Off-by-one III<br />

• Trigger allocations of <strong>the</strong> new size,<br />

<strong>Heap</strong>Alloc will eventually return free chunk<br />

off-by-one chunk free chunk interesting data<br />

SIZE<br />

FLAGS CHECK<br />

SUM<br />

…<br />

DATA<br />

• Checksum will fail, but heap continues…<br />

• Application still using interesting data, but<br />

can be overwritten using new allocation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!