Glibc heap exploitation — tcache poisoning, unsorted bin leak, IO_FILE FSOP
日本語の概要は準備中です。原文の説明を表示しています。
9 件 ・ 関連度順
概要と使いどころ
Glibc heap exploitation — tcache poisoning, unsorted bin leak, IO_FILE FSOP
日本語の概要は準備中です。原文の説明を表示しています。
Locate CCSPlayerInventory::m_pSOCache in CS2 server.dll / libserver.so via IDA Pro MCP and emit a fresh, minimal-unique signature or offset for the WeaponPaints gamedata entry "CCSPlayerInventory::m_pSOCache" (symbol CCSPlayerInventory_m_pSOCache). This is a STRUCT MEMBER OFFSET (schema netvar). Resolve the CCSPlayerInventory class layout via the schema system; m_pSOCache is the CGCClientSharedObjectCache pointer member. Cross-check: CCSPlayerInventory methods load this pointer and pass it to CGCClientSharedObjectCache methods (the GetItemInLoadout shortlist is a strong caller-side witness). Trigger: CCSPlayerInventory_m_pSOCache, CCSPlayerInventory::m_pSOCache
日本語の概要は準備中です。原文の説明を表示しています。
从逆向走到可用利用 (Working Exploit) 的全链路工程化方法。 适用场景:拿到了二进制 + 漏洞点 + 目标环境,需要写出一个能稳定打通的 exploit(不是只能本地复现一下、远程一打就崩的脚本)。 覆盖三大方向:栈溢出 / 堆利用 / 内核 pwn。强调"CTF 本地通 → 真实远程稳定打通"的工程差距:libc 版本错配、堆喷射时序、SMEP/SMAP/KASLR、栈对齐、远程缓冲。 核心工具链:pwntools + GEF/pwndbg + ROPgadget/Ropper + one_gadget + libc-database + qemu-system 内核调试。 触发关键词:pwn、栈溢出、堆溢出、ROP、ret2libc、ret2csu、one_gadget、libc-database、堆利用、tcache、fastbin、unsorted bin、kernel pwn、kROP、SMEP、SMAP、KASLR、modprobe_path、pwntools、GEF、pwndbg。
日本語の概要は準備中です。原文の説明を表示しています。
Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.
日本語の概要は準備中です。原文の説明を表示しています。
Implement multi-layer LLM caching with exact match, semantic similarity, and provider-side prompt caching. Reduce API costs by 30–70%, cut latency, and improve throughput using Redis, GPTCache, and provider caching APIs.
日本語の概要は準備中です。原文の説明を表示しています。
Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one/null, and leveraging tcache/fastbin/unsortedbin attacks for arbitrary write or code execution.
日本語の概要は準備中です。原文の説明を表示しています。
DiT 计算模块(L3):把**已定位的 DiT 计算瓶颈**落成特性级选档与实施—— 量化档(W8A16 / W4A16 / W8A8 系列 / W4A4 / MXFP8 / FA 量化)、稀疏(rf_v2 / ada_bsa)、 缓存(DiTCache / AttentionCache / 时间步优化)、编译启用(MindieSDBackend / Pattern 融合 / ACLGraph) 的**开不开、开哪一档、怎么开、怎么复验**;依据是 `docs/zh/features/*`(特性真源)+ framework-integration/references/framework-support-matrix.md(支持状态)。 即使用户只说"这个模型怎么加速""量化/稀疏/Cache 怎么选怎么开""要不要开量化、开哪一档""这个档位开了有没有效果" 而未提 profiling,也应触发。 **入口条件**:瓶颈点已明确(用户带一句实测锚点,或编排层交付标签)时由域入口 `performance-optimization` 按标签分发到本技能;**瓶颈未明("怎么加速 / 跑通 / 采 profile")先走 `model-auto-optimization` 定位**,不在本技能内做占比分析。 near-miss:多卡并行形态 / 通信掩盖 / TP·offload 选型 → `dit-parallel-opt`;VAE 解码段与 host 固定开销 → 各自模块(VAE / host);单算子实现级实测选型(mindie_bench)→ `benchmark-dev`; 需要新增 pattern / 算子才能落地本档 → `pattern-dev` / `operator-dev`;框架侧开关与使能验证 → `framework-integration`;量化器位级契约与精度对齐(编码公式 / 舍入 / scale 粒度)→ `quantization-dev`;精度验收判据 → `accuracy-gate`;数字入库口径 → `perf-gate`。
日本語の概要は準備中です。原文の説明を表示しています。
Cache dynamic and static responses on Netlify's CDN from Functions, Edge Functions, and proxies. Use when you add caching or cache-control headers to a function response, tune cache TTL or stale-while-revalidate, set up the durable cache, vary a cache key by query/header/cookie/country/language, purge or invalidate the cache by site or cache tag, use the programmatic Cache API (caches.open/match/put) or @netlify/cache helpers (fetchWithCache/cacheHeaders/getCacheStatus), speed up an expensive API call, add ISR or on-demand revalidation, or debug why a response is or isn't cached via the Cache-Status header.
日本語の概要は準備中です。原文の説明を表示しています。
Locate CCSPlayerInventory::GetItemInLoadout in CS2 server.dll / libserver.so via IDA Pro MCP and emit a fresh, minimal-unique signature or offset for the WeaponPaints gamedata entry "CCSPlayerInventory::GetItemInLoadout" (symbol CCSPlayerInventory_GetItemInLoadout). Non-virtual inventory method resolving a player's loadout item. Shortlist via callers inside CCSPlayerInventory code that walk the loadout item cache (m_pSOCache / CGCClientSharedObjectCache), and via the CSO/econ loadout message paths. The function takes an item definition index + loadout slot and returns the matching CEconItemView — the body iterates a small item list comparing definition indices and loadout slots. Trigger: CCSPlayerInventory_GetItemInLoadout, CCSPlayerInventory::GetItemInLoadout
日本語の概要は準備中です。原文の説明を表示しています。