Zum Hauptinhalt springen
Intelligence View
⚡ tsecurity.de Intelligence

Getting RCE without an info leak

Hi,

I have a question to the more experienced exploit devs:

I'm currently on a challenge where I'm exploiting a heap-based buffer OOB write. I'm able to overwrite the arena completely wherever I want (malloc_state, tcache, ...) and I'm also able to arbitrarily malloc() any sized buffer and write attacker controlled bytes to that new buffer, multiple times.

I'm struggling though because the binary has no infoleak or anything, it's not a server/daemon based binary where I can launch an info leak first and bypass ASLR like that. It's the last challenge, a difficult challenge to say the least. But I feel like the ability to poison tcache and then call malloc on any tcachebin (and do this N times) is a powerfull primitive, and I get this itch that this should be powerfull enough to do some feng shui stuff that gets me RCE.

I'm wondering what techiques has gotton you leakless RCE before? Stuff like house of Roman isn't possible because I'm on glibc 2.43 (latest) so safelinking is present. Could anyone point me in the right direction? House of Apples 2 also needs STDOUT which I don't have.

Details:

It's a Linux 64bit ELF binary, all protections enabled (aslr, stack canaries, pie and full relro) with glibc 2.43.

submitted by /u/Lmao_vogreward_shard
[link] [comments]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Getting RCE without an info leak

Thematisch verwandte Begriffe: Getting, without, info, leak · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
News ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

↗ Original-Quelle