Heap memory vulnerability utilization method in Zig language

Yuyang Chen · 2022

In software security, heap memory vulnerability is a common type of vulnerability. However, heap memory vulnerabilities can only lead to the collapse of the program in most cases. In order to achieve the purpose of getshell, it is still necessary to construct and use it. Zig language is a development-oriented programming language and will have more applications in the future. Based on the mechanism and principle of heap memory implementation in zig language, this paper finds several methods to exploit heap memory vulnerabilities, which can achieve the attack effect of writing eight-byte data at any writable address and applying for any address, respectively. On this basis, some corresponding defense methods are proposed, which provides ideas for the utilization and defense of heap memory vulnerabilities in binary security.

Read the paper · More papers on PaperTik