Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Heap feng shui

From Wikipedia, the free encyclopedia

Incomputer security,heap feng shui (also known asheap grooming[1]) is a technique used inexploits to facilitatearbitrary code execution.[2] The technique attempts to manipulate the layout of theheap by making heap allocations of carefully selected sizes. It is named afterfeng shui, an ancient Chinese system of aesthetics that involves the selection of precise alignments in space.

Operation

[edit]

The term is general and can be used to describe a variety of techniques for bypassingheap protection strategies. The paper often credited with naming the technique, "Heap Feng Shui in JavaScript",[3] used it to refer to an exploit in which adangling pointer was aligned with a portion of an attacker-controlled chunk. However, it has also found usage incapture the flag events to describe attacks that exploit characteristics of heap layout, such as the spacing between chunks.[4]

See also

[edit]

References

[edit]
  1. ^"What is a "good" memory corruption vulnerability?". Google Project Zero. June 26, 2015. Retrieved2020-11-11.
  2. ^"Heaps and Bounds". Trend Micro. September 3, 2007. Archived fromthe original on 2011-07-17. Retrieved2009-08-10.
  3. ^"Heap Feng Shui in Javascript"(PDF).BlackHat. Black Hat Europe. Retrieved11 October 2018.
  4. ^Keith, Bruno."Baby Feng Shui".GitHub. Retrieved19 June 2018.

External links

[edit]


Stub icon

Thiscomputer security article is astub. You can help Wikipedia byexpanding it.

Retrieved from "https://en.wikipedia.org/w/index.php?title=Heap_feng_shui&oldid=1115670998"
Categories:
Hidden category:

[8]ページ先頭

©2009-2025 Movatter.jp