You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

软件安全Attack Lab第5阶段ROP攻击段错误问题求助

Debugging Your Attack Lab Phase 5 ROP Chain & Answering Your Questions

Hey there, let's tackle your questions first, then dive into why your ROP chain is causing a segmentation fault.


Your Core Questions Explained

1. Why do we need to calculate the sum of %rsp and an address offset?

With ASLR (Address Space Layout Randomization) enabled, the stack's base address changes every time the program runs. Your cookie string is stored directly on the stack, so we can't hardcode its address—we need a dynamic way to locate it.

%rsp holds the current top of the stack when your ROP gadgets start executing. By adding the fixed offset between %rsp (at that moment) and the cookie string's position on the stack, we can reliably compute the string's actual address, regardless of ASLR's randomization.

Looking at your intended ROP logic, you're trying to use the lea (%rdi, %rsi, 1), %rax gadget to perform an addition: rdi + rsi = cookie string address.

Here's the flow:

  • First, we save %rsp into %rdi (so %rdi holds the starting stack address)
  • We pop the offset into %rax because pop is one of the easiest ways to load a constant into a register with ROP
  • Then we move that offset from %rax to %rsi (since the lea gadget uses %rsi as the source register for the addition)
  • Finally, the lea gadget computes the sum, giving us the cookie string's address in %rax

Why Your ROP Chain Is Causing a Segmentation Fault

The biggest issue is that you've misidentified almost all your gadgets. You're confusing instruction bytes with immediate data values in other instructions—these aren't valid executable gadgets for your intended operations. Let's break down the critical mistakes:

1. Invalid Gadget for mov %rsp, %rax

Your step 1 gadget:

401ae6: b8 27 48 89 e0 mov $0xe0894827,%eax;401aeb: c3

This doesn't move %rsp into %rax—it loads the immediate value 0xe0894827 into %eax. The bytes 48 89 e0 are part of the immediate data, not an executable instruction. You need to find a gadget where the executable bytes are 48 89 e0 c3 (the actual mov %rsp, %rax instruction followed by a ret).

2. Invalid Gadget for mov %rax, %rdi

Your step 2 gadget:

401a2d: 8d 87 48 89 c7 90 lea -0x6f3876b8(%rdi),%eax;401a33: c3

This executes a lea instruction, not mov %rax, %rdi. The bytes 48 89 c7 are part of the offset for the lea operation, not a standalone mov instruction. You need a gadget with executable bytes 48 89 c7 c3.

3. Invalid Gadgets for Register Moves (Steps 5-7)

For steps 5-7, you're trying to move values between registers (movl %eax, %edx, movl %edx, %ecx, movl %ecx, %esi), but your gadgets are all storing immediate values to memory (e.g., movl $0xc390c289,(%rdi)). Again, you're picking bytes from immediate data instead of valid executable instructions.


Fixing Your ROP Chain

Here's a corrected approach for your ROP sequence:

  1. Gadget: 48 89 e0 c3 (find where this byte sequence exists in the binary) → mov %rsp, %rax; ret
  2. Gadget: 48 89 c7 c3 → mov %rax, %rdi; ret (saves stack pointer to %rdi)
  3. Gadget: 58 c3 → pop %rax; ret (loads your offset 0x48 into %rax)
  4. Offset: 0x48 (your calculated offset, correct if the string is 72 bytes from %rsp at step 1)
  5. Gadget: 48 89 c6 c3 → mov %rax, %rsi; ret (moves offset to %rsi)
  6. Gadget: 48 8d 04 37 c3 → lea (%rdi, %rsi, 1), %rax; ret (calculates cookie string address)
  7. Gadget: 48 89 c7 c3 → mov %rax, %rdi; ret (puts string address into %rdi for touch3)
  8. Address: touch3 address (you confirmed this is correct)
  9. Cookie String: Your null-terminated cookie string (confirmed correct)

To fix your current chain, re-scan the binary for valid gadgets that match the exact instruction sequences you need—don't confuse immediate data bytes with executable instructions.


内容的提问来源于stack exchange,提问作者user7151309

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:32:56