SEED Buffer Overflow实验:shellcode地址定位及return address覆盖问询
Nice work figuring out the offset to overwrite the return address already—that's half the battle! When it comes to locating your shellcode's address in the SEED Buffer-Overflow Lab (Ubuntu 12.04 32-bit), here are the most reliable methods you can use:
1. Debug with GDB to Inspect the Stack Directly
This is the most precise method, especially since you're already using debug tools to calculate offsets:
- First, compile your vulnerable program with debug symbols and necessary flags (to disable stack protections):
Thegcc -g -fno-stack-protector -z execstack vulnerable.c -o vulnerable-fno-stack-protectorturns off stack canaries, and-z execstackmakes the stack executable—both required for this lab. - Launch GDB with your program:
gdb ./vulnerable - Set a breakpoint right before the vulnerable function (e.g., if the function is called
vuln, runb vuln). - Start the program with
r, and when it hits the breakpoint, usex/100x $espto dump the stack memory. Look for the region where your input buffer is stored. - If you're feeding input via stdin, you can use a unique pattern (like a string of incrementing characters) to mark your input's position on the stack. Once you see where this pattern lies, you can pinpoint exactly where your shellcode will reside.
- You can also get the exact address of the buffer with
p &buffer(replacebufferwith your actual buffer variable name)—your shellcode will start at this address if you place it at the beginning of your input.
2. Use Environment Variables to Store Shellcode
This method is great if you want to avoid dealing with stack alignment shifts in the vulnerable program:
- Export your shellcode as an environment variable (add NOP sleds
\x90to make address guessing forgiving):export SHELLCODE=$(python -c 'print "\x90"*50 + "\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\xb0\x0b\xcd\x80"') - Write a tiny C program to fetch the environment variable's address:
#include <stdio.h> #include <stdlib.h> int main() { char *shellcode_addr = getenv("SHELLCODE"); printf("Shellcode address: %p\n", shellcode_addr); return 0; } - Compile and run this helper program:
Note: The address might shift slightly when running the vulnerable program (due to different stack setup), so the NOP sled will help absorb small discrepancies.gcc getenv_addr.c -o getenv_addr && ./getenv_addr
3. Calculate Relative to the Return Address Offset
Since you already know the return address is at offset 36 from the buffer start, you can estimate the shellcode's address relative to this:
- If your input structure is
[NOP Sled][Shellcode][Padding (to offset 36)][Shellcode Address], the shellcode's address will bebuffer_start_address + length_of_nop_sled. - You can get
buffer_start_addressvia GDB (usingp &bufferas mentioned earlier), then adjust for the NOP sled length to get the exact jump target.
Pro Tips
- Always include a long enough NOP sled (
\x90bytes) before your shellcode. This gives you a "margin of error" if your address calculation is off by a few bytes—the CPU will just slide through the NOPs until it hits the shellcode. - Test incrementally: First confirm you can overwrite the return address with a known value (like a GDB breakpoint address) to ensure your offset is correct, then swap it out for your shellcode's address.
内容的提问来源于stack exchange,提问作者alond22
相关产品推荐
相关产品推荐

