rocky theme song
I can beat this problem. I can use dlmalloc to turn an int overflow to heap overflow into a pseudo UAF using a metadata overwrite so the overwritten chunk when freed is returned to the wrong free list so when it is allocated from that list it will overwrite the next chunk with system controlled object data so I can leak out a function pointer from the overwritten object.
I just need to find the right objects and control them well....