Linux Heap Exploitation Part 1: Learn Real-World GLIBC Attacks

Linux Heap Exploitation Part 1: Learn Real-World GLIBC Attacks

🎙 TechBlazes 👥 13K 📅 December 29, 2025 ⏱ 291 min 👁 706 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

heapGLIBCexploitationmallocsecurity

Summary

This video is a comprehensive tutorial on Linux heap exploitation, focusing on real-world GLIBC attacks. It covers the fundamentals of GLIBC and malloc, then dives into several exploitation techniques including House of Force, Fastbin Dup, Unsafe/Safe Unlink, House of Orange, and one-byte overflows. The course is hands-on, using HeapLAB, pwntools, and pwndbg to demonstrate each technique. The instructor explains the underlying heap internals, such as chunk metadata, the top chunk, and free lists, before showing how to turn vulnerabilities into arbitrary write primitives and achieve code execution. The video is structured into modules with clear timestamps, making it easy to follow. It is intended for CTF players, exploit developers, and those interested in understanding heap exploitation. The content is technically demanding but well-explained, with practical examples and challenges. The video also includes setup instructions for the environment and resources for further learning.

142 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides high-value information by systematically teaching heap exploitation from the ground up. It explains the internals of GLIBC’s malloc and how to leverage them for exploitation. The argumentation is solid, as each technique is justified by the underlying heap mechanics, and the demonstrations are clear and reproducible. The instructor emphasizes understanding over rote memorization, which enhances the educational value. The techniques covered are well-known and documented in the security community, adding to the credibility of the content.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by accurately explaining GLIBC internals and heap exploitation techniques. It references the ‘Malloc Maleficarum’ paper for the House of Force, which is a well-known source in the field. The title accurately reflects the content, which is a detailed tutorial on real-world GLIBC heap attacks. The video does not cite external sources within the content, but the techniques are established and widely discussed in cybersecurity literature. The description includes links to the creator’s social media and support pages, but no direct references to academic or technical sources.

185 words

Title / Content Match

The title accurately reflects the content, which is a comprehensive introduction to Linux heap exploitation focusing on real-world GLIBC attacks.

Quality & Reliability

8/10

The video is a detailed technical tutorial on heap exploitation, grounded in GLIBC internals. It provides accurate explanations of malloc behavior and exploitation techniques, with practical demonstrations. The content is well-structured and based on established knowledge in the field, though it does not cite external sources within the video itself.

Chapters

Cited Sources

  • TechBlazes Supporters — Mentioned in the description as a link to premium courses.
  • Buy Me a Coffee — Support link provided in the description.
  • TechBlazes Medium — Link to TechBlazes' Medium page for additional content.
  • TechBlazes LinkedIn — Professional profile link.
  • TechBlazes Pinterest — Social media link.
  • TechBlazes Reddit — Social media link.

Concurring Sources

  • Malloc Maleficarum — The paper that introduced the House of Force technique, referenced in the video.
  • CTF Wiki - Heap Exploitation — A comprehensive resource on heap exploitation techniques, including House of Force.

Contribution & Novelties

The video provides a comprehensive and structured introduction to heap exploitation, making complex topics accessible through hands-on demonstrations. It covers multiple techniques in depth, from House of Force to one-byte overflows, and explains the underlying heap internals. The use of HeapLAB and pwntools provides practical experience. The video is a valuable resource for those new to heap exploitation, offering a clear learning path.

Pour aller plus loin :

  • Malloc Maleficarum — The original paper describing House of Force and other techniques.
  • Heap Exploitation - CTF Wiki — Detailed explanations of heap exploitation techniques.
  • pwntools documentation — Official documentation for the pwntools framework used in the video.

106 words

Radar Profile

The radar profile shows high scores in quantity of information, technical level, and reliability, indicating a dense and technically rigorous tutorial. The quality of information is also high, though slightly lower, possibly due to the lack of external citations within the video itself.

Reliability 8/10