📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Heap protection on Win 7

Topic created on: August 23, 2010 15:06 CDT by voila .

hello guys ..

After stack , now i want to learn about heap memory protections on windows 7 ... and anything and everything about heap layout on Windows ..

can you guide me where i should look (any link or blog or pdf )... i search google , bt i got link for stack memroy more than heap ... and moreover not relavant info ..


thanks
byeee

  tosanjay     August 24, 2010 06:48.56 CDT
I do not have references specific to Windows 7, but following may provide some info (google to find online):
1. Heap of Risk
2. HeapShield
3. Smashing the Heap for Fun and Profit
4. An introduction to Win32 Heap Overflows by Lin0xx

  voila     August 24, 2010 08:55.45 CDT
> tosanjay: I do not have references specific to Windows 7, but following may provide some info (google to find online):
> 1. Heap of Risk
> 2. HeapShield
> 3. Smashing the Heap for Fun and Profit
> 4. An introduction to Win32 Heap Overflows by Lin0xx


Thanks tosanjay :) .. i will look at this .. :)

  psylocn   August 25, 2010 05:27.13 CDT
"Bypassing Browser Memory Protections" Alexander Sotirov, Mark Dowd
"Attacking the Vista Heap" Ben Hawkes
"Windows Vista Heap Management Enhancements" Adrian Marinescu
"Reliable Windows Heap Exploits" Conover Horovitz
"Understanding and bypassing Windows Heap Protection" Nicolas Waisman
"HEAPS ABOUT HEAPS" Brett Moore
"Engineering Heap Overflows with JavaScript" Jake Honoroff Mark Daniel
Charlie Miller
"Heap Feng Shui in JavaScript" Alexander Sotirov

  j00ru     August 25, 2010 17:23.39 CDT
Although not strictly related to Windows 7, the Practical Windows/2003 Heap Exploitation paper from Blackhat USA 2009 (by John McDonald and Chris Valasek) is also a very thorough reference, imho ;)

  voila     August 25, 2010 22:10.10 CDT
hii .

Thanks to psylocn and j00ru :)  .

j00ru .. your link for blackhat paper is really awesome .. thanks .

thanks a lot both psylocn and j00ru  :)

  j00ru     August 26, 2010 03:09.47 CDT
You're welcome ;>
BTW. i search google , bt i got link for stack memroy more than heap ... and moreover not relavant info ..
please keep in mind that using Google or whatever search engine you like, is really a major part of a RE's work. Useful to learn it ;)

  voila     August 26, 2010 04:19.12 CDT
> j00ru: You\'re welcome ;>
> BTW. i search google , bt i got link for stack memroy more than heap ... and moreover not relavant info ..
> please keep in mind that using Google or whatever search engine you like, is really a major part of a RE\'s work. Useful to learn it ;)


Ok j00ru .. i will keep it in mind and implement it .. thanks a lot for your suggestions  :) :)

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit