beginnerFreebinary-exploitationpwnformat-stringprintf
Course

Introduction to Format String Attacks

One missing `"%s"` and a program hands you its memory. `printf(buf)` where `buf` came from a user is not a printing bug - it is an interpreter running code the attacker wrote. This course takes that single mistake apart and builds every primitive it yields, in the order they depend on each other: f

5
Modules
11
Lectures
7
Hands-on labs
5h
Of material

About this course

One missing "%s" and a program hands you its memory.

printf(buf) where buf came from a user is not a printing bug - it is an interpreter running code the attacker wrote. This course takes that single mistake apart and builds every primitive it yields, in the order they depend on each other: find where your input lands on the stack, read memory you were never shown, leak the addresses that mitigations are hiding, write arbitrary bytes with %n, copy a value you are not allowed to see with the width specifier, redirect a call through the GOT, and - with no leak, no win() and no writable function pointer anywhere - write a full ROP chain over the saved return address of main one byte at a time.

Seven labs, each with a complete worked solution written against flashlib. The first six take one primitive each; the last one gives you a single line of input and asks for a shell. Every challenge runs on the same image the exploits were validated against, so the writeup you read is the exploit that ran.

The last lesson is the other half: why a bug with a compiler warning older than most of the people exploiting it is still shipped, and the one rule that prevents it.

Syllabus

5 modules, 11 lectures, 5 quizzes and 7 hands-on challenges.

  1. The Format String

    What printf actually is, why it can be lied to, and the one number every later technique depends on.

    • What a Format String Actually Is
    • Position, and Where the Arguments Come From

    1 quiz 1 hands-on challenge

  2. Reading Memory

    From 'whatever is on the stack' to 'whatever address I name' - and from an address to a defeated mitigation.

    • Arbitrary Read
    • Leaking PIE, the Canary, and libc
    • Debugging a Format String

    1 quiz 1 hands-on challenge

  3. Writing Memory

    %n turns a printing bug into an arbitrary write. The mechanism is one line; making it land is a procedure.

    • Writing With %n
    • Building a Write, End to End

    1 quiz 1 hands-on challenge

  4. The * Specifier

    Width taken from an argument. Chain it to %n and you have copied a value you were never shown.

    • The * Specifier

    1 quiz 1 hands-on challenge

  5. Taking Control

    Where to put the write: a function pointer, or - when there is not one - the saved return address of main.

    • Hijacking a Function Pointer
    • ROP From a Format String, With No Leak
    • Automation, and Why the Bug Still Exists

    1 quiz 3 hands-on challenges

Part of

This course is a leg of a longer track.

  • The Pwny way.

5 modules about 5 hoursOpened from your Arena account

Take Introduction to Format String Attacks

Create an account to open the lectures and launch this course's labs in the browser.

Create a free account