GithubHelp home page GithubHelp logo

gmh5225 / villoc Goto Github PK

View Code? Open in Web Editor NEW

This project forked from wapiflapi/villoc

0.0 0.0 0.0 54 KB

Visualization of heap operations.

License: MIT License

Shell 1.88% C++ 22.62% Python 48.38% C 23.42% Makefile 2.40% CMake 1.31%

villoc's Introduction

Villoc

Villoc is a heap visualisation tool, it's a python script that renders a static html file. An example can be seen here: http://wapiflapi.github.io/villoc/, this is villoc running on an exploit of PlaidCTF 2015's challenge PlaidDB.

How to

The easiest way to use villoc is probably to run the following command and open out.html in a browser.

ltrace ./target |& villoc.py - out.html;

It is probably a good idea to disable ASLR for repeatable results and to use a file to pass the ltrace to villoc because otherwise the target's error output will be interleaved and might confuse villoc sometimes.

setarch x86_64 -R ltrace -o trace ./target; villoc.py trace out.html;

Using DynamoRIO

The problem with ltrace is that it doesn't track calls to malloc from other libraries or from within libc itself.

Please check https://github.com/wapiflapi/villoc/tree/master/tracers/dynamorio for (easy!) instructions for using a DynamoRIO tool to achieve full tracing.

Annotations

Villoc's input should look like ltrace's output, other tracers should output compatible logs. Villoc also listens to annotations of the following form:

@villoc(comma separated annotations) = <void>`

When using this it's possible to mark certain block as being significant which makes analyzing villoc's output that much easier.

Annotations from C code through DynamoRIO.

When using the dynamorio tracer there is a hack to easily inject annotations from a target's source code:

sscanf("Format string %d %d, FOO %s", "@villoc", 1, 2, "BAR");

Will inject Format string 1 2 into villoc's log and add the FOO and BAR tags to the block affected by the next memory operation.

image

Which malloc

This has been made with glibc's dl_malloc in mind. But it should work for other implementations, especially if you play with the --header and --footer options to indicate how much overhead the targeted malloc adds to the user data.

villoc's People

Contributors

wapiflapi avatar bestpig avatar naim94a avatar sam-b avatar eax64 avatar themaks avatar ampotos avatar clubby789 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.