You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

栈缓冲区溢出示例程序疑问:为何未触发预期异常?

Why Your Stack Buffer Overflow Example Isn't Behaving As Expected

Hey there! Let's break down why your assembly program didn't crash or produce garbage output like you expected, even though you tried to access memory beyond the allocated stack buffer.

1. You're Overwriting the Exit Code With a Hardcoded Value

First, look at the _start section of your code:

_start:
call sum
movl %eax, %ebx  # You save sum's return value to ebx...
movl $15, %ebx   # ...but immediately overwrite ebx with 15!
movl $1, %eax
int $0x80

No matter what happens inside the sum function, your program will always exit with a status code of 15. This masks any errors that might have occurred in sum—you're seeing the exit code you hardcoded, not evidence of a crash.

2. You're Modifying the Return Address, But It Didn't Trigger an Immediate Crash

Let's map out the stack layout inside the sum function to understand what -8(%ebp) actually points to:

  • When you call sum, the CPU pushes the address of the next instruction (the movl %eax, %ebx line in _start) onto the stack as the return address.
  • Inside sum, pushl %ebp saves the old base pointer to the stack, and movl %esp, %ebp sets the new base pointer to this position.
  • subl $4, %esp allocates 4 bytes for a local variable, so -4(%ebp) is your local buffer, and -8(%ebp) is the return address pushed by the call instruction.

Your code modifies this return address to 10 (first $5, then adding $5). When sum executes ret, it jumps to address 0xA. On some 32-bit systems, low memory addresses might be mapped as executable (or accidentally contain valid instructions), so the program doesn't crash immediately. But this isn't normal behavior—it's a coincidence that masked the overflow.

3. This Example Isn't Typical of Real-World Stack Overflows

Real stack buffer overflows usually involve user input overwriting the return address (not hardcoding the overwrite), and the error is immediately visible. To make your example show clear overflow behavior, try this modified version:

Modified Overflow Example

.section .data
.section .text
.globl _start
_start:
call sum
# Keep sum's return value as the exit code (no hardcoded 15!)
movl %eax, %ebx
movl $1, %eax
int $0x80

.type sum, @function
sum:
pushl %ebp
movl %esp, %ebp
subl $4, %esp  # Allocate 4 bytes for local variable
# Overwrite the return address with an invalid memory address
movl $0xdeadbeef, -8(%ebp)
movl $10, %eax  # Set a return value we can check if the function exits normally
movl %ebp, %esp
popl %ebp
ret

Compile and Run

as -gstabs+ overflow.s -o overflow.o
ld overflow.o -o overflow
./overflow
echo $?

This time, you should see a Segmentation fault—the program tries to jump to 0xdeadbeef, which is an invalid memory address. The exit code will be 139 (the standard Linux code for a segmentation fault), clearly showing the overflow caused an error.

Wrap-Up

Your original code did attempt to trigger a stack overflow, but the hardcoded exit code and a lucky coincidence with the modified return address hid the error. The adjusted example will give you the clear crash behavior you expected from a stack buffer overflow.

内容的提问来源于stack exchange,提问作者Niranjan M.R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 06:57:22