栈缓冲区溢出示例程序疑问:为何未触发预期异常?
Hey there! Let's break down why your assembly program didn't crash or produce garbage output like you expected, even though you tried to access memory beyond the allocated stack buffer.
1. You're Overwriting the Exit Code With a Hardcoded Value
First, look at the _start section of your code:
_start: call sum movl %eax, %ebx # You save sum's return value to ebx... movl $15, %ebx # ...but immediately overwrite ebx with 15! movl $1, %eax int $0x80
No matter what happens inside the sum function, your program will always exit with a status code of 15. This masks any errors that might have occurred in sum—you're seeing the exit code you hardcoded, not evidence of a crash.
2. You're Modifying the Return Address, But It Didn't Trigger an Immediate Crash
Let's map out the stack layout inside the sum function to understand what -8(%ebp) actually points to:
- When you call
sum, the CPU pushes the address of the next instruction (themovl %eax, %ebxline in_start) onto the stack as the return address. - Inside
sum,pushl %ebpsaves the old base pointer to the stack, andmovl %esp, %ebpsets the new base pointer to this position. subl $4, %espallocates 4 bytes for a local variable, so-4(%ebp)is your local buffer, and-8(%ebp)is the return address pushed by thecallinstruction.
Your code modifies this return address to 10 (first $5, then adding $5). When sum executes ret, it jumps to address 0xA. On some 32-bit systems, low memory addresses might be mapped as executable (or accidentally contain valid instructions), so the program doesn't crash immediately. But this isn't normal behavior—it's a coincidence that masked the overflow.
3. This Example Isn't Typical of Real-World Stack Overflows
Real stack buffer overflows usually involve user input overwriting the return address (not hardcoding the overwrite), and the error is immediately visible. To make your example show clear overflow behavior, try this modified version:
Modified Overflow Example
.section .data .section .text .globl _start _start: call sum # Keep sum's return value as the exit code (no hardcoded 15!) movl %eax, %ebx movl $1, %eax int $0x80 .type sum, @function sum: pushl %ebp movl %esp, %ebp subl $4, %esp # Allocate 4 bytes for local variable # Overwrite the return address with an invalid memory address movl $0xdeadbeef, -8(%ebp) movl $10, %eax # Set a return value we can check if the function exits normally movl %ebp, %esp popl %ebp ret
Compile and Run
as -gstabs+ overflow.s -o overflow.o ld overflow.o -o overflow ./overflow echo $?
This time, you should see a Segmentation fault—the program tries to jump to 0xdeadbeef, which is an invalid memory address. The exit code will be 139 (the standard Linux code for a segmentation fault), clearly showing the overflow caused an error.
Wrap-Up
Your original code did attempt to trigger a stack overflow, but the hardcoded exit code and a lucky coincidence with the modified return address hid the error. The adjusted example will give you the clear crash behavior you expected from a stack buffer overflow.
内容的提问来源于stack exchange,提问作者Niranjan M.R

