heap-exploitation
Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.
Security Assessment
About heap-exploitation
An expert playbook for exploiting glibc/ptmalloc2 heap vulnerabilities. It documents the malloc_chunk memory layout, the different bin types (tcache, fastbin, unsortedbin, smallbin, largebin) with their linking and ordering behavior, and the key global structures such as main_arena, mp_, and tcache_perthread_struct. Leak methods are covered for both libc base (via unsortedbin/smallbin fd/bk pointers or stdout FILE leaks) and heap base (via tcache/fastbin fd pointers or use-after-free reads), including the safe-linking / PROTECT_PTR pointer obfuscation introduced in glibc 2.32 with decode and encode helper snippets.
Attack techniques are organized by glibc version because the available primitives change across releases: fastbin dup, unsortedbin attack, unlink, House of Force/Spirit and off-by-one on pre-2.26; tcache poisoning and tcache dup on 2.26-2.28; tcache-key bypass and House of Botcake on 2.29-2.31; safe-linking-aware poisoning on 2.32-2.33; and the removal of __malloc_hook/__free_hook/__realloc_hook at 2.34 that pushes exploitation toward _IO_FILE, exit_funcs, and TLS_dtor_list. A vulnerability-pattern table maps UAF, double free, heap overflow, off-by-one/null, and uninitialized reads to concrete exploitation paths.
It is intended for CTF and real-world binary exploitation once a heap bug has been identified, and includes a decision tree for picking an attack based on the available primitive and glibc version. Tooling notes cover pwndbg heap inspection (heap, bins, tcachebins, vis_heap_chunks), shellphish's how2heap reference exploits, heapinspect, and pwntools for resolving libc symbols. Related skills handle stack ROP, format-string leaks, arbitrary-write-to-RCE, and protection bypass, while deeper material on the House-of techniques and IO_FILE/FSOP vtable hijacking lives in companion reference files.
FAQ
Which glibc versions does this playbook cover?
It spans pre-2.26 (no tcache) through 2.34+ where the malloc hooks are removed, calling out version-specific primitives such as tcache keys (2.29-2.31) and safe-linking (2.32+).
What is safe-linking and how do I deal with it?
Safe-linking (PROTECT_PTR, glibc >= 2.32) XORs a chunk's fd pointer with (chunk_addr >> 12). The doc provides obfuscate/deobfuscate helpers, but you need a heap address leak to encode or decode pointers.
When should I use this instead of the stack ROP skill?
Use it when the corruption is in heap memory; for stack-based overflows the doc routes you to the stack-overflow-and-rop skill.
What tools does it recommend for inspecting the heap?
pwndbg commands (heap, bins, tcachebins, fastbins, vis_heap_chunks), shellphish's how2heap for reference exploits, heapinspect, and pwntools for resolving libc symbols.
How do I leak a libc address from the heap?
Free a chunk larger than the tcache range (or fill the tcache) so it lands in the unsortedbin, then read its fd/bk, which points into main_arena and resolves to the libc base.
Install heap-exploitation
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
yaklang/hack-skills