缓冲区溢出差异:Linux虚拟机可行但Windows主机示例执行失败
缓冲区溢出测试:Windows与Linux环境的差异问题
我正在通过Jon Erickson所著的《黑客:剥削的艺术》(Hacking: The Art of Exploitation)学习缓冲区溢出技术,目标是通过向命令行参数传入超出字符数组存储能力的字节触发缓冲区溢出,将精确值0xdeadbeef写入value变量。以下是测试代码overflow_example.c:
#include <stdio.h> #include <string.h> int main(int argc, char *argv[]){ int value = 5; char buffer_one[8], buffer_two[8]; strcpy(buffer_one, "one"); strcpy(buffer_two, "two"); printf("[BEFORE] buffer_two is at %p and contains '%s'\n", buffer_two, buffer_two); printf("[BEFORE] buffer_one is at %p and contains '%s'\n", buffer_one, buffer_one); printf("[BEFORE] value is at %p and is %d (0x%08x)\n",&value, value, value); printf("\n[STRCPY] copying %d bytes into buffer_two\n\n", strlen(argv[1])); strcpy(buffer_two, argv[1]); printf("[AFTER] buffer_two is at %p and contains '%s'\n", buffer_two, buffer_two); printf("[AFTER] buffer_one is at %p and contains '%s'\n", buffer_one, buffer_one); printf("[AFTER] value is at %p and is %d (0x%08x)\n", &value, value, value); return 0; }
在Windows 10 x86_64主机上,我仅能成功将0x0000beef写入value变量,尝试写入0xdeadbeef时得到异常值。我计算出buffer_two(地址0061FF0C)与value(地址0061FF1C)的距离为16字节,因此先用16个字符A填充缓冲区。
Windows 10 x86_64主机的beef测试示例
$ ./overflow_example.exe `perl -e 'print "\x41"x16 . "\xEF\xBE"'` [BEFORE] buffer_two is at 0061FF0C and contains 'two' [BEFORE] buffer_one is at 0061FF14 and contains 'one' [BEFORE] value is at 0061FF1C and is 5 (0x00000005) [STRCPY] copying 18 bytes into buffer_two [AFTER] buffer_two is at 0061FF0C and contains 'AAAAAAAAAAAAAAAA∩╛' [AFTER] buffer_one is at 0061FF14 and contains 'AAAAAAAA∩╛' [AFTER] value is at 0061FF1C and is 48879 (0x0000beef)
Windows 10 x86_64主机的deadbeef测试示例
$ ./overflow_example.exe `perl -e 'print "\x41"x16 . "\xEF\xBE\xAD\xDE"'` [BEFORE] buffer_two is at 0061FF0C and contains 'two' [BEFORE] buffer_one is at 0061FF14 and contains 'one' [BEFORE] value is at 0061FF1C and is 5 (0x00000005) [STRCPY] copying 18 bytes into buffer_two [AFTER] buffer_two is at 0061FF0C and contains 'AAAAAAAAAAAAAAAA?▐' [AFTER] buffer_one is at 0061FF14 and contains 'AAAAAAAA?▐' [AFTER] value is at 0061FF1C and is 56895 (0x0000de3f)
但在同一设备的QEMU Kali Linux虚拟机上运行相同代码却能成功写入0xdeadbeef,请问这是什么原因?
同一设备上的QEMU Kali Linux虚拟机测试示例
$ ./overflow_example.exe `perl -e 'print "\x41"x16 . "\xEF\xBE\xAD\xDE"'` [BEFORE] buffer_two is at 0x7ffedc85505c and contains 'two' [BEFORE] buffer_one is at 0x7ffedc855064 and contains 'one' [BEFORE] value is at 7ffedc85506c and is 5 (0x00000005) [STRCPY] copying 18 bytes into buffer_two [AFTER] buffer_two is at 0x7ffedc85505c and contains 'AAAAAAAAAAAAAAAA?▐' [AFTER] buffer_one is at 0x7ffedc855064 and contains 'AAAAAAAA?▐' [AFTER] value is at 0x7ffedc85506c and is -559038737 (0xdeadbeef)
内容的提问来源于stack exchange,提问作者Tobi Bobb
相关产品推荐
相关产品推荐

