【问题标题】:Demonstrate buffer overflow in C in Ubuntu 13.04在 Ubuntu 13.04 中演示 C 中的缓冲区溢出
【发布时间】:2014-02-26 20:05:00
【问题描述】:

作为我任务的一部分,我必须在我的 linux 机器中演示 stackoverflow。

我的盒子配置: 操作系统:Ubuntu 13.04

GCC 版本:4.6.3

我尝试使用标志 -fno-stack-protector 编译程序,程序成功编译,但是当我触发堆栈溢出时出现分段错误错误。我怎样才能显示实际的o / p。 缓冲区溢出 Pgm:

int main(int argc, char**argv)
 {
   int authentication=0;
   char cUsername[10], cPassword[10];
   strcpy(cUsername, argv[1]);
   strcpy(cPassword, argv[2]);
   if(strcmp(cUsername, "admin") == 0 && strcmp(cPassword, "adminpass") == 0)
{
       authentication = 1;}
if(authentication)
{
       printf("Access granted");} 
else
{
       printf("Wrong username and password");
    }return 0;}

如果我给一个像 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA A 那么它应该显示已授予访问权限,但现在它显示分段错误

【问题讨论】:

  • 你想溢出栈执行shell代码吗?
  • 是的,我想将一个长字符串复制到一个小字符数组中。
  • 这听起来更像是堆栈损坏而不是堆栈溢出。
  • Okie.....那么我怎样才能成功地演示它..?
  • 如果你有一个 SIGSEGV 那么你已经证明了它:你在一个小缓冲区中写入了太多数据,你被操作系统抛出了一个段冲突。你想具体展示什么?

标签: c gcc ubuntu-13.04


【解决方案1】:

如果您使用以下参数启动程序,我的 c 编译器会发生以下情况: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA B:

int main(int argc, char**argv)
{
  int authentication=0;
  char cUsername[10], cPassword[10];

  strcpy(cUsername, argv[1]);
  // now cUsername contains "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
  // and authentication contains "0x41414141" because it has been overwritten because of the
  // buffer overflow of cUsername

  strcpy(cPassword, argv[2]);
  //now cPassword contains "B"

  if(strcmp(cUsername, "admin") == 0 && strcmp(cPassword, "adminpass") == 0)
  {
    // strings are different so we don't get here
    authentication = 1;
  }

  if (authentication)
  {
    // authentication still contains 0x41414141 therefore we get here
    printf("Access granted");
  } 
  else
  {
    printf("Wrong username and password");
  }

  // here we will get a segmentation fault, because the return adress which is on the
  // stack will have been overwritten with 0x41414141 which is most probably an
  // invalid address
  return 0;
}

顺便说一句,如果你的代码格式正确,它会更容易阅读。

重要

根据您的系统,“已授予访问权限”可能不会被打印出来,因为如果输出被缓冲,则输出缓冲区通常会在主函数返回之后清空并且因为程序段错误以前,输出缓冲区永远不会被清空,消息也永远不会显示。尝试在“授予访问权限\n”字符串的末尾添加一个\n。

【讨论】:

  • 总是可以用fflush(stdout);刷新输出缓冲区
  • 所以我想在那个 o/p 到来时获得消息访问权限,但它直接导致分段错误
  • 用调试器运行你的程序,你会看到段错误发生的确切位置。
猜你喜欢
  • 1970-01-01
  • 2011-09-07
  • 1970-01-01
  • 2012-02-05
  • 1970-01-01
  • 2021-09-16
  • 1970-01-01
  • 2015-12-26
  • 2019-04-17
相关资源
最近更新 更多