tl;dr
- Giving size > 48 causes heap OOB r/w of 16 bytes
- Use OOB r/w get leaks and overwrite objects for rip control
tl;dr
tl;dr
type.tl;dr
Tilde operator.tl;dr
strncat in merge allows for an overwrite onto the next region tl;dr
__malloc_hook to one_gadgettl;dr
stdin stucture till main_arena.fastbin chunks to get overlapping chunk and leak.__malloc_hook using fastbin attack.tl;dr
char candle counter stored in the wax structure and trigger uaf.