Note that there are some explanatory texts on larger screens.

plurals
  1. POOverflow over scanf("%8s", string)?
    primarykey
    data
    text
    <p>I know it's possible to overflow ordinary code:</p> <p><strong>char string[9];</strong></p> <p>scanf("%s", string). </p> <p>But is it possible to overflow scanf("%8s", string)? 8 is just an example.</p> <p>I know "%8s" works like a delimit, but I also notice when I input string longer than 8 chars, the program will terminate due to:</p> <p><strong>* stack smashing detected *</strong>: ./a.out terminated</p> <p>======= Backtrace: =========</p> <p>...</p> <p>Obviously there's a flag that detects stack smashing turned on by GCC by default. Since this is a stack smashing, then my guess is that it is still possible to overflow and execute arbitrary code.</p> <p>Contrary to normal overflow that mangles the caller of scanf("%s"), if scanf("%8s") can overflow, it will overflow within scanf function so that when scanf try to return, control is gained.</p> <p>But scanf is a syscall that requires mode-switch (switching from user mode into kernel mode), and internally it will call stuff like read to the stdin etc. So not sure if we can overflow in kernel mode or something..</p> <p>Comments are welcome!!</p> <p><strong><em>UPDATE >></em></strong> </p> <p>char string[9] is assumed in the above example. char string[8] in following real code.</p> <p>The question is really about the seeming conflicting story between safe scanf("%8s") and GCC abortion due to stack smashing.</p> <p>Simplified code:</p> <pre><code>void foo(pass some pointer) { char input[8]; int input_number = 0; while (1) { // looping console printf some info; scanf("%8s", input); input_number = atoi(input); if ((strlen(input) == 1) &amp;&amp; (strncmp(input, "q", 1) == 0)) { input_number = -1; } switch (input_number) { case -1: to quit the console if input = 'q'; default: to print info that pointer refers to; ... } } } </code></pre> <p>Note: </p> <ol> <li>foo is called by someone else.</li> <li>Though string is 8 bytes in real code with "%8s", I don't think this lead to smashing.</li> </ol>
    singulars
    1. This table or related slice is empty.
    plurals
    1. This table or related slice is empty.
    1. This table or related slice is empty.
 

Querying!

 
Guidance

SQuiL has stopped working due to an internal error.

If you are curious you may find further information in the browser console, which is accessible through the devtools (F12).

Reload