๐Ÿง 
QualityGo

Glibc Heap Exploitation

by xalgord

Glibc Heap Exploitation is a Quality skill for Claude Code, published by xalgord in xalgorix.

852 stars153 forkson xalgord/xalgorixAdded 2026/08/12+1% in starsRepository updated 2026/08/11
ai-agentai-securityautomationautonomous-pentestingbug-bountycybersecurityethical-hackinggolangpenetration-testingpentestpentesting-toolsreconsecuritysecurity-researchsecurity-toolstypescriptvulnerability-detectionvulnerability-scanner
Install in seconds
Install Glibc Heap Exploitation
Copy Glibc Heap Exploitation into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/xalgorix/xalgorix/tree/main/internal/tools/skills/data/binary-exploitation/exploiting-glibc-heap-vulnerabilities ~/.claude/skills/exploiting-glibc-heap-vulnerabilities

Requires Node.js. Downloads this skill only โ€” not the rest of the repository โ€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/xalgorix/xalgorix.git

Clones the whole repository, then copy the skillโ€™s own directory into your skills folder yourself.

In this catalog

Source file
internal/tools/skills/data/binary-exploitation/exploiting-glibc-heap-vulnerabilities/SKILL.md in xalgord/xalgorix
Installs to
~/.claude/skills/exploiting-glibc-heap-vulnerabilities
Collection
One of 51 skills cataloged from this repository
Category
Quality โ€” 1354 skills

What Glibc Heap Exploitation does

Glibc Heap Exploitation outlines methods for exploiting ptmalloc2 bugs such as use-after-free, double-free, overflow, and off-by-one in authorized testing. It covers leaks, tcache poisoning, safe-linking, and modern mitigation-aware workflows.

Glibc Heap Exploitation is cataloged under Quality on DirSkills. Glibc Heap Exploitation comes from a repository tagged ai-agent, ai-security, automation, autonomous-pentesting and bug-bounty.

Documentation

README

Exploiting glibc Heap Vulnerabilities

When to Use

  • During authorized exploitation of programs that dynamically manage memory with malloc/calloc/free and contain use-after-free, double-free, heap overflow, or off-by-one (poison-null-byte) bugs.
  • When the stack is not the corruption surface but you control freed-chunk contents, chunk size fields, or allocation ordering, and want to convert that into an arbitrary read/write or code-pointer overwrite.
  • When selecting a bin-specific primitive: tcache poisoning, fast-bin dup, unsorted-bin attack, large-bin attack, House of Force/Einherjar/Botcake, etc.
  • When you must account for the target glibc version's mitigations (tcache key, safe-linking, removed malloc hooks).

Critical: Concepts/Steps Most Often Missed

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Glibc Heap Exploitation

  • What else does xalgord publish alongside Glibc Heap Exploitation?

    Glibc Heap Exploitation is one of 51 skills that DirSkills catalogs from xalgord/xalgorix, the repository it ships in. Its siblings there include AFL++ Fuzzing, AI Security Guardrails and AI-Assisted Vulnerability Discovery. Each one is a separate skill with its own page in this directory, installs the same way Glibc Heap Exploitation does, and is maintained by xalgord in that same repository. The rest of the collection is listed on the xalgord/xalgorix page.

  • How does Glibc Heap Exploitation compare to other Quality skills?

    Glibc Heap Exploitation ranks #925 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Glibc Heap Exploitation against them. Open each page to compare what they document and how they install.

More from xalgord/xalgorix

Glibc Heap Exploitation is one of 51 skills cataloged on DirSkills from xalgord/xalgorix.

See all 51 skills โ†’
๐Ÿงช
3w ago

AFL++ Fuzzing

AFL++ Fuzzing performs coverage-guided fuzzing of compiled binaries to find crashes and hangs. Use it when instrumenting a target, preparing seed corpora, and triaging unique findings during security testing.
Quality
852153
๐Ÿ›ก๏ธ
2026/07/20

AI Security Guardrails

Implement input and output validation guardrails to prevent prompt injection, jailbreaks, PII leaks, and off-topic responses in LLM-powered applications.
AI Engineering
852151
๐Ÿ›ก๏ธ
2026/07/20

AI-Assisted Vulnerability Discovery

Uses LLMs to generate valid fuzzing seeds, evolve grammars from coverage feedback, and help reproduce and triage crashes in authorized security research. Also supports evidence-based analysis of Burp traffic and report drafting.
AI Engineering
852151
๐Ÿ›ก๏ธ
2026/07/20

API Abuse Detection with Rate Limiting

Implements API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and scraping attacks. Includes distributed Redis-backed limiters with verification steps.
DevOps
852151
๐Ÿ”
3w ago

API Authentication Testing

API Authentication Testing checks REST API auth for bypasses, weak JWT validation, exposed endpoints, and token lifecycle issues. Use it when validating login, session, refresh, or API key protections before release.
Quality
852153
๐Ÿ”
2026/07/20

API Fuzzing with RESTler

Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences.
Quality
852151