Published onJuly 18, 2024Pwnable.tw - Tcache Tearpwnable.twheaptcachetcache-dupdouble-freeunsorted-bin-attackfake-chunkfree-hook-overwriteUtilizing double free to create a fake chunk in the BSS section of the ELF and freeing the chunk into the unsorted bin by using Unsorted Bin Attack to leak libc and overwrite __free_hook.
Published onMarch 14, 2024HTB - Cyber Apocalypse 2024 - Pwn - Deathnotepwnhtbcyber-apocalypse24heapunsorted-binUtilizing unsorted bin to get a libc arena leak and calling system with user-controlled heap-chunk's data.
Published onFebruary 17, 2024PUCon' 24 - Userspace - ChampcatpuconpwnheapuafUtilizing Heap Use-After-Free to load the flag into user-controlled chunk and read it.