Introduction to Format String Attacks
One missing `"%s"` and a program hands you its memory. `printf(buf)` where `buf` came from a user is not a printing bug - it is an interpreter running code the attacker wrote. This course takes that single mistake apart and builds every primitive it yields, in the order they depend on each other: f
- 5
- Modules
- 11
- Lectures
- 7
- Hands-on labs
- 5h
- Of material
About this course
One missing "%s" and a program hands you its memory.
printf(buf) where buf came from a user is not a printing bug - it is an interpreter running code the attacker wrote. This course takes that single mistake apart and builds every primitive it yields, in the order they depend on each other: find where your input lands on the stack, read memory you were never shown, leak the addresses that mitigations are hiding, write arbitrary bytes with %n, copy a value you are not allowed to see with the width specifier, redirect a call through the GOT, and - with no leak, no win() and no writable function pointer anywhere - write a full ROP chain over the saved return address of main one byte at a time.
Seven labs, each with a complete worked solution written against flashlib. The first six take one primitive each; the last one gives you a single line of input and asks for a shell. Every challenge runs on the same image the exploits were validated against, so the writeup you read is the exploit that ran.
The last lesson is the other half: why a bug with a compiler warning older than most of the people exploiting it is still shipped, and the one rule that prevents it.
Syllabus
5 modules, 11 lectures, 5 quizzes and 7 hands-on challenges.
The Format String
What printf actually is, why it can be lied to, and the one number every later technique depends on.
- What a Format String Actually Is
- Position, and Where the Arguments Come From
1 quiz 1 hands-on challenge
Reading Memory
From 'whatever is on the stack' to 'whatever address I name' - and from an address to a defeated mitigation.
- Arbitrary Read
- Leaking PIE, the Canary, and libc
- Debugging a Format String
1 quiz 1 hands-on challenge
Writing Memory
%n turns a printing bug into an arbitrary write. The mechanism is one line; making it land is a procedure.
- Writing With %n
- Building a Write, End to End
1 quiz 1 hands-on challenge
The * Specifier
Width taken from an argument. Chain it to %n and you have copied a value you were never shown.
- The * Specifier
1 quiz 1 hands-on challenge
Taking Control
Where to put the write: a function pointer, or - when there is not one - the saved return address of main.
- Hijacking a Function Pointer
- ROP From a Format String, With No Leak
- Automation, and Why the Bug Still Exists
1 quiz 3 hands-on challenges
Part of
This course is a leg of a longer track.
- The Pwny way.
5 modules about 5 hoursOpened from your Arena account
Take Introduction to Format String Attacks
Create an account to open the lectures and launch this course's labs in the browser.
Create a free account