Sinisterly
Buffer overflow examples - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: C, C++, & Obj-C (https://sinister.li/Forum-C-C-Obj-C)
+--- Thread: Buffer overflow examples (/Thread-Buffer-overflow-examples)

Pages: 1 2


Buffer overflow examples - Merkuri - 03-10-2013

Since I see a lot of peoples to write tutorials in internet for buffer overflow, when they even aren't familiar with the stack and copy from other tutorials I decide to give some examples I hope that programmers will understand them. The example are on C language

Example 1.
Spoiler:
Code:
#include <lib 1> #include <lib 2> #include <lib ...> char buffer[8]; char *program_to_run= "something.exe"; void main( char *args[] ) { gets( buffer ); exec( program_to_run ); }

In this example I have create a char variable "buffer" with 8 bits size, this program should run something.exe, in this case the program should be vulnerable.

Example 2
Spoiler:
Code:
#include <lib 1> #include <lib ...> void function(char *str) { char buffer[16]; strcpy(buffer,str); } void main() { char large_string[256]; int i; for( i = 0; i < 255; i++) large_string[i] = 'A'; function(large_string); }
In this example again I have create a char with name bufffer and bla bla bla.The intresting here is the function she copies a supplied string without bounds checking by
using strcpy() instead of strncpy(). You may get segmentation violation.


Example 3
Spoiler:
Code:
#include <lib 1> #include <lib ...> void getInput(){ char buffer[8]; gets(buffer); puts(buffer); } void main(){ getinput(); return 0; }
Here I have create char with name bla bla bla... This simple will get a message from the user and put it on the screen. If the message is to large your application will be vulnerable.


How to avoid buffer overflow?
Spoiler:
1. Avoid using library files included with the compiler. If an hacker find vulnerability in those files all applications that include them will be vulnerable.
2.Strlcpy and Strlcat. An alternative, being employed by OpenBSD, is the strlcpy(3) and strlcat(3) they are a minimalist, statically-sized buffer approach that provides C string copying and concatenation with a different (and less error-prone) interface.

Those are the only recommendations I can do for now, I'm not very experience developer I like more exploting them. I'm sure that you will be able to find help in coding forums.


Those examples are only on buffer overflow but there are more vulnerabilities in C language like heap overflow.


RE: Buffer overflow examples - superMAUS - 05-05-2014

(03-10-2013, 11:30 PM)Synchro Wrote: Since I see a lot of peoples to write tutorials in internet for buffer overflow, when they even aren't familiar with the stack and copy from other tutorials I decide to give some examples I hope that programmers will understand them. The example are on C language

Example 1.
Spoiler:
Code:
#include <lib 1> #include <lib 2> #include <lib ...> char buffer[8]; char *program_to_run= "something.exe"; void main( char *args[] ) { gets( buffer ); exec( program_to_run ); }

In this example I have create a char variable "buffer" with 8 bits size, this program should run something.exe, in this case the program should be vulnerable.

Just because it overwrites doesnt make it vulnerable in the sense its exploitable. Considering the lack of handled user input you cant exploit this.


RE: Buffer overflow examples - 0xDEAD10CC - 07-20-2014

Just because a programmer's ignorance to check the size of the string being passed over to the destination from a source pointer might result in a buffer overflow doesn't make strcpy() a bad function.


RE: Buffer overflow examples - Christ - 07-20-2014

(07-20-2014, 08:23 PM)0xDEAD10CC Wrote: Just because a programmer's ignorance to check the size of the string being passed over to the destination from a source pointer might result in a buffer overflow doesn't make strcpy() a bad function.

Only if you fail at using strcpy() does it turn into a bad function.

Code:
void func(char *userdata) { char buf[256]; strcpy(buf, userdata); }

If you code like this you shouldn't be coding because it's neither functional nor excusable.


RE: Buffer overflow examples - 3SidedSquare - 07-21-2014

(03-10-2013, 11:30 PM)Merkuri Wrote:
Spoiler:
In this example I have created a char variable "buffer" with 8 bits size, this program should run something.exe, in this case the program should be vulnerable.

Spoiler:
In this example again I have created a char with name bufffer and bla bla bla.The interesting thing here is the function she copies a supplied string without checking bounds by
using strcpy() instead of strncpy(). You may get segmentation violation.

Spoiler:
Here I have created char with name bla bla bla... This will simply get a message from the user and put it on the screen. If the message is to large your application will be vulnerable.

Spoiler:
1. Avoid using library files included with the compiler. If a hacker finds a vulnerability
...
they are a minimal,
...
only recommendations I have for now, I'm not a very experienced developer, I like exploting buffer overflows more
I'm afraid I share the opinions of the posters above, what kind of recommendation is "Avoid using library files included with the compiler"? The entire point of libraries is to learn how to use them to make your programming easier.


RE: Buffer overflow examples - 0xDEAD10CC - 07-21-2014

(07-20-2014, 11:38 PM)Christ Wrote: Only if you fail at using strcpy() does it turn into a bad function.

Code:
void func(char *userdata) { char buf[256]; strcpy(buf, userdata); }

If you code like this you shouldn't be coding because it's neither functional nor excusable.

I don't understand. Are you agreeing with me then? This is exactly as I just said. :S


RE: Buffer overflow examples - Christ - 07-21-2014

(07-21-2014, 04:48 AM)0xDEAD10CC Wrote: I don't understand. Are you agreeing with me then? This is exactly as I just said. :S

Yeah I was giving you blackup.


RE: Buffer overflow examples - w00t - 07-21-2014

(07-20-2014, 08:23 PM)0xDEAD10CC Wrote: Just because a programmer's ignorance to check the size of the string being passed over to the destination from a source pointer might result in a buffer overflow doesn't make strcpy() a bad function.

Yes it does, using strncpy, which is 2-6 more keystrokes, prevents that from happening, ever.


RE: Buffer overflow examples - 0xDEAD10CC - 07-21-2014

(07-21-2014, 05:59 AM)w00t Wrote: Yes it does, using strncpy, which is 2-6 more keystrokes, prevents that from happening, ever.

My point still stands, just because there's the possibility of it being vulnerable doesn't make it a bad function. Yes there are alternatives that can and probably should be used, but if you choose to use strcpy(), then it's the programmer's ignorance that determines whether it's vulnerable or not, and/or unknowing.

There is still absolutely no reason to grab some third party library just because strcpy() doesn't check the size.

Btw, functions like strncpy() don't guarantee null-termination. People use those functions because they are safer, but not many realize this, and thus might end up forgetting to set '\0' within the string. Non-terminated strings are still bad, because it would result in an overrun. The way strncpy() works, it was really probably designed for inserting characters within a string, but it had been re-identified by programmers to be used for strings all the time, just because it's safer. If you don't understand that the null terminator is implicitly NOT put anywhere in the buffer by this function, then I see it as just as much work as checking the length with using strcpy() quite honestly, although strcpy() guarantees the null terminator.

Functions are not bad, for a programmer to blame a function is ignorance. Nobody else is writing the code for you.


RE: Buffer overflow examples - phyrrus9 - 07-21-2014

@Merkuri seriously, who taught you how to program?

braces dont go there
your tabbing sucks
you have really poor theory
all of your overflows look like something not even a first grader would do (they aren't that stupid).

Show some well written real world examples.