Login Register






Buffer overflow examples filter_list
Author
Message
RE: Buffer overflow examples #11
OK, I swear I don't remember why I had say " 1. Avoid using library files included with the compiler. If an hacker find vulnerability in those files all applications that include them will be vulnerable.", when I have some time I will fix this tutorial.

(07-21-2014, 10:47 PM)phyrrus9 Wrote: @Merkuri seriously, who taught you how to program?

braces dont go there
your tabbing sucks
you have really poor theory
all of your overflows look like something not even a first grader would do (they aren't that stupid).

Show some well written real world examples.


1. Someone so good, that you will never be.
2. Who said that?
3. I don't see anything wrong with my tabbing
(2 and 3 http://www.open-std.org/jtc1/sc22/wg21/d.../n3690.pdf)
4. For what theory are you tolking, I said those are just example(for BEGINNERS) who had fallow other tutorials without example(this was my motive to write this before time.
and about the "real life example", if you help me to write a virtual machine or interpreter, I don't mind to make real life example which is for "absolute" beginners, because I don't see where else C is still used(except Linux ofcourse). Now don't say that C is used in microcontrollers, the situation there is completly different.

Reply

RE: Buffer overflow examples #12
@phyrrus9
Please read:
http://thecodelesscode.com/case/94?topic=naming
[Image: jWSyE88.png]

Reply

RE: Buffer overflow examples #13
If you honestly think that you would need a vm to test a buffer overrun, you're insane..here is an example:

Code:
#include <stdio.h> main(argc, argv) int argc; char * const argv[]; { FILE *fp = fopen(argv[1], "r"); //ignore the error in not null checking char ibuf[1024], fmbuf[30]; //ignore static allocation out of laziness fscanf(fp, "^[\n]\n", fmbuf); fprintf(stdout, fmbuf, 1, 0b0100, 0x32); }

this, in conjunction with an awkward format string, could trigger a print of the stack pointer.

Reply

RE: Buffer overflow examples #14
Let me elaborate.. if the input was the following:

%d%d%d%c%p%p%p%p

it will print:

Code:
(int)1 (int)4 (int)0x32 //we dont care fp ibuf fmbuf sp

Reply

RE: Buffer overflow examples #15
(07-25-2014, 03:19 AM)phyrrus9 Wrote: If you honestly think that you would need a vm to test a buffer overrun, you're insane..here is an example:

Code:
#include <stdio.h> main(argc, argv) int argc; char * const argv[]; { FILE *fp = fopen(argv[1], "r"); //ignore the error in not null checking char ibuf[1024], fmbuf[30]; //ignore static allocation out of laziness fscanf(fp, "^[\n]\n", fmbuf); fprintf(stdout, fmbuf, 1, 0b0100, 0x32); }

this, in conjunction with an awkward format string, could trigger a print of the stack pointer.

Why did you leave out the return declaration for main()? And where is fclose()? (// ignore not properly closing file handles)

Here's an obvious example in a minimalistic form:
Code:
#include <stdio.h> #include <string.h> int main(void) { char encrypted[5] = "$A4R"; // derived eventually from some complex series of algorithms (?) char buffer[5]; char user_intput[] = "?????haha"; printf("Original: %s\n", encrypted); strcpy(buffer, user_intput); // Fail printf("Overwritten: %s\n", encrypted); }

Reply

RE: Buffer overflow examples #16
(07-29-2014, 05:53 AM)0xDEAD10CC Wrote: Why did you leave out the return declaration for main()? And where is fclose()? (// ignore not properly closing file handles)

Here's an obvious example in a minimalistic form:
Code:
#include <stdio.h> #include <string.h> int main(void) { char encrypted[5] = "$A4R"; // derived eventually from some complex series of algorithms (?) char buffer[5]; char user_intput[] = "?????haha"; printf("Original: %s\n", encrypted); strcpy(buffer, user_intput); // Fail printf("Overwritten: %s\n", encrypted); }

Probably typo, donnu the thread is old.

Reply