Back to Skills

heap-exploitation

Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.

1,281stars175forksUpdated 7/5/2026

Security Assessment

Safe(100/100)
Security Score100/100

About heap-exploitation

An expert playbook for exploiting glibc/ptmalloc2 heap vulnerabilities. It documents the malloc_chunk memory layout, the different bin types (tcache, fastbin, unsortedbin, smallbin, largebin) with their linking and ordering behavior, and the key global structures such as main_arena, mp_, and tcache_perthread_struct. Leak methods are covered for both libc base (via unsortedbin/smallbin fd/bk pointers or stdout FILE leaks) and heap base (via tcache/fastbin fd pointers or use-after-free reads), including the safe-linking / PROTECT_PTR pointer obfuscation introduced in glibc 2.32 with decode and encode helper snippets.

Attack techniques are organized by glibc version because the available primitives change across releases: fastbin dup, unsortedbin attack, unlink, House of Force/Spirit and off-by-one on pre-2.26; tcache poisoning and tcache dup on 2.26-2.28; tcache-key bypass and House of Botcake on 2.29-2.31; safe-linking-aware poisoning on 2.32-2.33; and the removal of __malloc_hook/__free_hook/__realloc_hook at 2.34 that pushes exploitation toward _IO_FILE, exit_funcs, and TLS_dtor_list. A vulnerability-pattern table maps UAF, double free, heap overflow, off-by-one/null, and uninitialized reads to concrete exploitation paths.

It is intended for CTF and real-world binary exploitation once a heap bug has been identified, and includes a decision tree for picking an attack based on the available primitive and glibc version. Tooling notes cover pwndbg heap inspection (heap, bins, tcachebins, vis_heap_chunks), shellphish's how2heap reference exploits, heapinspect, and pwntools for resolving libc symbols. Related skills handle stack ROP, format-string leaks, arbitrary-write-to-RCE, and protection bypass, while deeper material on the House-of techniques and IO_FILE/FSOP vtable hijacking lives in companion reference files.

FAQ

Which glibc versions does this playbook cover?

It spans pre-2.26 (no tcache) through 2.34+ where the malloc hooks are removed, calling out version-specific primitives such as tcache keys (2.29-2.31) and safe-linking (2.32+).

What is safe-linking and how do I deal with it?

Safe-linking (PROTECT_PTR, glibc >= 2.32) XORs a chunk's fd pointer with (chunk_addr >> 12). The doc provides obfuscate/deobfuscate helpers, but you need a heap address leak to encode or decode pointers.

When should I use this instead of the stack ROP skill?

Use it when the corruption is in heap memory; for stack-based overflows the doc routes you to the stack-overflow-and-rop skill.

What tools does it recommend for inspecting the heap?

pwndbg commands (heap, bins, tcachebins, fastbins, vis_heap_chunks), shellphish's how2heap for reference exploits, heapinspect, and pwntools for resolving libc symbols.

How do I leak a libc address from the heap?

Free a chunk larger than the tcache range (or fill the tcache) so it lands in the unsortedbin, then read its fd/bk, which points into main_arena and resolves to the libc base.

All Files

3 files
HOUSE_OF_TECHNIQUES.md8.9 KB
View
SKILL.md8.6 KB
View
IO_FILE_EXPLOITATION.md8.5 KB
View

Install heap-exploitation

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill