30.07.2014 Views

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

Attacking the Vista Heap - 2008

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Canary leak<br />

• Leak of a chunk header of known size and<br />

state gives leak of heap wide canary value<br />

C1 = L1 ^ K1<br />

C2 = L2 ^ K2<br />

C3 = L3 ^ K3<br />

C4 = L4 ^ K1 ^ K2 ^ K3<br />

• Can <strong>the</strong>n use overflow to change size,<br />

allocated/free, flags, FWD/BCK links etc

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!