Похожие чаты

Q: Is it a bug? A: Yes, it can be categorized

as buffer overflow vulnerability.

Q: Why doesn't it crash?
A: Dereferencing wild pointer is like opening a box of chocolate, you never know what you're gonna get!

Q: Be more specific!
A: When compiled in debug mode, allocator try to allocate the memory block at the end of a page, and mark the next page as nonwritable. For example, if you allocate 16 bytes, the allocator may place it at 4095 - 16 = 4079. When you write the 16th byte (4096), which resides in the next non-writeable page, hardware notice the OS that your program is malfunctioning.

Q: Why is my bug (malloc(5) and accessing [13]) not detected?
A: Unaligned memory access slows down the program; on some platforms, the program will even crash! Memory allocators tend to align the returning address to prevent such tragedy. On x86_64, my allocator (ptmalloc2 by glibc) aligns the address to a multiple of 16 bytes. So if you allocate 5 bytes, instead of returning 4095 - 5, the allocator returns 4095 - 16. Now you have to access 16 bytes past the returning address to trigger the protection.

Q: How can I detect the bug?
A: Use awesome tools, like ASan in Clang and Valgrind.

3 ответов

13 просмотров

amazing

Похожие вопросы

Обсуждают сегодня

Господа, а что сейчас вообще с рынком труда на делфи происходит? Какова ситуация?
Rꙮman Yankꙮvsky
29
А вообще, что может смущать в самой Julia - бы сказал, что нет единого стандартного подхода по многим моментам, поэтому многое выглядит как "хаки" и произвол. Короче говоря, с...
Viktor G.
2
@Benzenoid can you tell me the easiest, and safest way to bu.y HEX now?
Živa Žena
20
This is a question from my wife who make a fortune with memes 😂😂 About the Migration and Tokens: 1. How will the old tokens be migrated to the new $LGCYX network? What is th...
🍿 °anton°
2
30500 за редактор? )
Владимир
47
а через ESC-код ?
Alexey Kulakov
29
What is the Dex situation? Agora team started with the Pnetwork for their dex which helped them both with integration. It’s completed but as you can see from the Pnetwork ann...
Ben
1
Гайс, вопрос для разносторонее развитых: читаю стрим с юарта, нада выделять с него фреймы с определенной структурой, если ли чо готовое, или долбаться с ринг буффером? нада у...
Vitaly
9
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
@lozuk how do I get my phex copies of my ehex from a atomic wallet, to move to my rabby?
Justfrontin 👀
11
Карта сайта