<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: 0x57Origin</title>
    <description>The latest articles on DEV Community by 0x57Origin (@0x57origin).</description>
    <link>https://dev.to/0x57origin</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3633954%2F92e5cd60-42b9-4be5-a163-d4a5878295bc.png</url>
      <title>DEV Community: 0x57Origin</title>
      <link>https://dev.to/0x57origin</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/0x57origin"/>
    <language>en</language>
    <item>
      <title>Introduction to Network-Based Exploit Development</title>
      <dc:creator>0x57Origin</dc:creator>
      <pubDate>Mon, 28 Sep 2026 22:35:47 +0000</pubDate>
      <link>https://dev.to/0x57origin/introduction-to-network-based-exploit-development-jp0</link>
      <guid>https://dev.to/0x57origin/introduction-to-network-based-exploit-development-jp0</guid>
      <description>&lt;p&gt;The first step here is to develop a C server, a tiny one of course, with safety features turned off, and start it on localhost. But we need to learn one thing first: what exactly is a buffer overflow.&lt;/p&gt;

&lt;h2&gt;
  
  
  Buffer Overflow
&lt;/h2&gt;

&lt;p&gt;A buffer overflow happens when a program writes more data to a fixed-size memory container, which is called a buffer. So anything more than what it is supposed to hold, and boom: overflow. Memory is contiguous, so guess what, the extra data does not go away. It spills over and overwrites whatever data is next to it in RAM. It's like trying to pour 5 gallons of water into a 1-gallon bucket. It floods the floor around it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Stack Memory Diagram
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Ff0a3e6d0-9278-44b0-b8c0-f404c2346035" class="article-body-image-wrapper"&gt;&lt;img width="760" height="950" alt="Diagram" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Ff0a3e6d0-9278-44b0-b8c0-f404c2346035"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When a function runs, it sets aside a "stack frame" in memory, which is a temporary chunk of memory that a computer sets aside every single time a function is called.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. Normal State (Everything fits)
+------------------------+
| Saved Return Address   | -&amp;gt; Tells the CPU where to return when the function finishes
+------------------------+
| Local Buffer (64 bytes)| -&amp;gt; The container meant for your input data
+------------------------+

---

2. Overflowed State (Too much data sent)
+------------------------+
| [ A A A A A A A A ]    | -&amp;gt; OVERWRITTEN! The return address is now corrupted with "AAAA" (0x41414141)
+------------------------+
| [ A A A A A A A A ]    | -&amp;gt; Spilled over past the 64-byte boundary
+------------------------+
| Local Buffer (64 bytes)| -&amp;gt; Completely full of data
+------------------------+
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;So why does it cause a crash?&lt;/p&gt;

&lt;p&gt;When the function is done running, the CPU looks at the saved return address to figure out what code to execute next. Now, because we have replaced that data with a bunch of A's, it looks at that memory address instead. Where is that memory address coming from? Well, I wrote it, right? When I sent a flood of data over the network, like a hundred A's, the input filled up the 64-byte buffer and kept spilling over and over. So whatever the CPU went back to do at the saved return address is now gone: the extra A's took it out and erased it. A equals 41 in hex. In computer language, the capital letter A is represented by the hexadecimal value 41. So when you sent four A's, you literally wrote 41 41 41 41 (0x41414141) straight into that memory slot. So the CPU now goes to that memory address and then crashes. A is also 65 in decimal, according to the ASCII table, that is not a magical number we can find but it is a a table we look up. So, when you convert 65 to hex it becomes 41. The math is quite simple. &lt;/p&gt;

&lt;p&gt;Math:&lt;/p&gt;

&lt;p&gt;Divide 65 by 16 and you will get = 4 remainder 1.&lt;br&gt;
The 4 is the first hex digit. 1. The 1 is the second hex digit. 65 decimal = 41 hex&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;65 ÷ 16 = 4 remainder 1
              ↓        ↓
              4        1

A = 41 in hex
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;So when we do simple division we get 65 ÷ 16 = 4.0625. But for hex, we do whole-number division:&lt;/p&gt;

&lt;p&gt;16 fits inside 65 4 times&lt;/p&gt;

&lt;p&gt;16 × 4 = 64&lt;/p&gt;

&lt;p&gt;65 - 64 = 1&lt;/p&gt;

&lt;p&gt;So:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;65 ÷ 16

16 × 4 = 64
65 - 64 = 1

= 4 with 1 left over
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;4 and 1 → 41 Hex.&lt;/p&gt;

&lt;p&gt;Summary:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;        65 ÷ 16

     16 goes into 65
          4 times

        16 × 4 = 64

        65 - 64 = 1


        FIRST DIGIT = 4
        SECOND DIGIT = 1

             ↓

           HEX = 41


ASCII says:

65 = A

So:

A = 65 decimal = 41 hex
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;We do need to understand hex (hexadecimal) to the tee, because in exploit development, hex is the native language. Every memory address, register value, and bad character you look at will be in hex. It kills my brain cells sometimes to figure out hex, but before we get into hex we need to understand what decimal is, or BASE-10.&lt;/p&gt;




&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Ff1ab3a73-2a18-4be9-bd46-bc6522dadf92" class="article-body-image-wrapper"&gt;&lt;img width="760" height="950" alt="Decimal" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Ff1ab3a73-2a18-4be9-bd46-bc6522dadf92"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Decimal (Base-10) and Hex (Base-16)
&lt;/h2&gt;

&lt;p&gt;Everyday counting we do from 0 to 9, but in digital form basically. 0-9 is 10 numbers, because 0 is the first number in computer language. Hex, on the other hand, uses 16 symbols. Decimal runs out of symbols after 9, so that is where hex comes in: after 9 comes A, B, C, D, E, F. Then it rolls over.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F455e6c72-ddd6-4811-b6dc-c49acf189bcd" class="article-body-image-wrapper"&gt;&lt;img width="2720" height="940" alt="Decimal to hex symbol table" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F455e6c72-ddd6-4811-b6dc-c49acf189bcd"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We have to memorize these numbers: A=10, B=11, C=12, D=13, E=14, F=15. From here, everything else is just multiplication.&lt;/p&gt;

&lt;p&gt;Now let's take 2 digits: 2 and F.&lt;/p&gt;

&lt;p&gt;The left digit is the 16s slot, and the right side, F, is the 1s slot. Same as 47 being four 10s and seven 1s.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F90683d42-633a-4681-8d98-9a9d9774c54d" class="article-body-image-wrapper"&gt;&lt;img width="760" height="428" alt="Decimal_Diagram2" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F90683d42-633a-4681-8d98-9a9d9774c54d"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Steps:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Left digit is 2. Multiply by 16, so 2 * 16 = 32.&lt;/li&gt;
&lt;li&gt;Right digit is F. F is just 15 (from the memorized list). It's the 1s slot, so 15 * 1 = 15.&lt;/li&gt;
&lt;li&gt;32 + 15 = 47. So 2F is 47.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That's the whole trick every single time: left digit times 16, plus right digit.&lt;/p&gt;

&lt;p&gt;So let's decipher what 3A is:&lt;/p&gt;

&lt;p&gt;3 * 16 = 48 and A * 1 = 10 * 1 = 10. So 48 + 10 = 58.&lt;/p&gt;

&lt;p&gt;Now, maybe another day we can do more math. For now, let's actually break some things, but that's not gonna happen yet, right? We need to know what a BIT is.&lt;/p&gt;




&lt;p&gt;A bit is one switch, which means it's either 0 or 1. Just yes or no, and that is it. So we line up 8 of them in a row. Now that just became a byte. Each switch in the row is worth double the one to its right, starting at 1 on the far right, and at the end count it up, it will be 255.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F88c7e134-ec70-43a1-823d-f1f48f96ca02" class="article-body-image-wrapper"&gt;&lt;img width="2720" height="760" alt="A byte: eight bits and their place values" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F88c7e134-ec70-43a1-823d-f1f48f96ca02"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now how do we do the byte math? To read a byte, whenever there is a 1, you grab that slot's value. Then add them up. You skip the slot with 0. Bytes max out at 255.&lt;/p&gt;

&lt;p&gt;SIMPLE RULE -&amp;gt; Write the 8 slot values. Look at the bits. Keep the slots with 1 and skip the slots with 0, boom. Let's do simple mathematics.&lt;/p&gt;

&lt;p&gt;Take the byte 01000001.&lt;/p&gt;

&lt;p&gt;Line the bits under their slots:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;128  64  32  16   8   4   2   1
 0   1   0   0    0   0   0   1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Slots with 1 can be kept only, anything else is gone, so now I can see we can only keep 1 and 64, which becomes 64+1 = 65. So 01000001 is 65 and 65 is also the letter A.&lt;/p&gt;

&lt;p&gt;65 is decimal, not hex. The byte 01000001 adds up to 65 in decimal. Same byte in hex would be 41. Almost like it's Halloween. 3 costumes.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F0cdacedd-d0b6-413c-9c1f-a8f3bbd9e54c" class="article-body-image-wrapper"&gt;&lt;img width="760" height="428" alt="Bit_Byte" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F0cdacedd-d0b6-413c-9c1f-a8f3bbd9e54c"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now the part you're really asking: why does that value mean the letter A?&lt;/p&gt;

&lt;p&gt;Because somebody decided it would. There's a lookup table called ASCII that maps numbers to characters. It's just an agreed-upon list. On that list, the number 65 is assigned to capital A. 66 is B, 67 is C, and so on. No math makes 65 "become" A. It's a dictionary, and the computer looks it up.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fa76f173d-b943-4c16-9b7a-2b578bad6389" class="article-body-image-wrapper"&gt;&lt;img width="2720" height="1011" alt="ASCII lookup showing 65 is A" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2Fa76f173d-b943-4c16-9b7a-2b578bad6389"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So how does 01000001 turn into 41 in hex?&lt;/p&gt;

&lt;p&gt;There is a trick here: we divide the 8 into 2, then it becomes 4, and each 4 is a hex. 01000001 splits into 0100 and 0001.&lt;/p&gt;

&lt;p&gt;Now read each group of 4 using slot values, but a group of 4 only has these slots: 8, 4, 2, 1.&lt;/p&gt;

&lt;p&gt;Left group 0100:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;8  4  2  1
0  1  0  0
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Only the 4 slot is on. So this group = 4.&lt;/p&gt;

&lt;p&gt;Right group 0001:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;8  4  2  1
0  0  0  1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Only the 1 slot is on. So this group = 1.&lt;/p&gt;

&lt;p&gt;Now add them both up and you get 41. Killed all my brain cells for today, man. That's why hex and bytes are best friends: 4 bits always make exactly one hex digit (0 to F), so 8 bits make exactly two hex digits. A byte is always two hex digits, every time.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F28ecc7b3-3eb8-46d2-8753-3e0ea4ef201c" class="article-body-image-wrapper"&gt;&lt;img width="760" height="428" alt="Bits_HEX" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F28ecc7b3-3eb8-46d2-8753-3e0ea4ef201c"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  The Vulnerable Server
&lt;/h2&gt;

&lt;p&gt;OS: Kali. I saved it as &lt;code&gt;server.c&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;stdio.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;      // Stands for input and output - printf()&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;string.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;     // String and memory functions&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;unistd.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;     // Gives you the raw system calls like -&amp;gt; read(), write(), and close()&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;arpa/inet.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;  // Gives you network address tools -&amp;gt; htons(), which flips your port number into the byte order the network expects.&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;
&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;(){&lt;/span&gt;
    &lt;span class="c1"&gt;// Socket is basically the network channel&lt;/span&gt;
    &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;sock&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;SOCK_STREAM&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="c1"&gt;// 0 is for accepting the default transport protocol, which is TCP.&lt;/span&gt;
    &lt;span class="c1"&gt;// htons just takes the port and converts it into a byte order that the network understands.&lt;/span&gt;
    &lt;span class="c1"&gt;// sockaddress is the address for the network channel&lt;/span&gt;
    &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;sockaddr_in&lt;/span&gt; &lt;span class="n"&gt;Sockaddress&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;htons&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;31337&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;}};&lt;/span&gt; &lt;span class="c1"&gt;// 0 is open, meaning listen on all my machine's IPs, not just one.&lt;/span&gt;
    &lt;span class="c1"&gt;// Bind = attach the address to the network channel.&lt;/span&gt;
    &lt;span class="c1"&gt;// sock is of course the socket network channel and we are binding it with the socket address.&lt;/span&gt;
    &lt;span class="c1"&gt;// (struct sockaddr*) is a generic label bind accepts; the * makes it -&amp;gt; pointer to.&lt;/span&gt;
    &lt;span class="c1"&gt;// &amp;amp;Sockaddress is the actual pointer to the sockaddr_in box we made earlier.&lt;/span&gt;
    &lt;span class="n"&gt;bind&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;sockaddr&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;Sockaddress&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Sockaddress&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
    &lt;span class="n"&gt;listen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;  &lt;span class="c1"&gt;// Start accepting incoming connections on the socket &amp;amp; 1 = how many callers can wait on hold while you're busy with one.&lt;/span&gt;
    &lt;span class="k"&gt;while&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;accept&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;))){&lt;/span&gt;
        &lt;span class="c1"&gt;// Remember we are the caller!&lt;/span&gt;
        &lt;span class="c1"&gt;// client is whoever connects to your network channel. The first 0 is the caller's info or address, so we will not log that, and since the caller is us and we are on localhost there is no point saving that. The second 0 -&amp;gt; do not save the size of the IP address either.&lt;/span&gt;

        &lt;span class="c1"&gt;// A char is one byte and we created a box holding 64 bytes.&lt;/span&gt;
        &lt;span class="c1"&gt;// Now we can't really put 512 bytes in the box; it will overflow.&lt;/span&gt;
        &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;64&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
        &lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;512&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt; &lt;span class="c1"&gt;// VULNERABILITY: Reads 512 bytes into a 64-byte buffer&lt;/span&gt;
        &lt;span class="n"&gt;close&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Compile code -&amp;gt; &lt;code&gt;gcc server.c -o server -fno-stack-protector -z execstack -no-pie&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Before we continue, read what I have to say first below!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F6a95cb96-da86-4380-972b-f0578d1382c1" class="article-body-image-wrapper"&gt;&lt;img width="760" height="428" alt="CPU_RAM_STACK" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.com%2Fuser-attachments%2Fassets%2F6a95cb96-da86-4380-972b-f0578d1382c1"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Stack Memory
&lt;/h2&gt;

&lt;p&gt;Stack memory is a region in RAM set aside for running functions. Every time a function is called, it grabs a small slice from there, which is called a FRAME. And why does it do that? Well, to hold its local variables and its return address. And what is the return address? The return address is the CPU's bookmark: when this function finishes, jump back here and keep going, but back to the FRAME. When a function is called, the slice or Frame is freed the instant the function finishes. So basically while the function runs it grabs that FRAME, uses it, then releases it. It is called a stack because frames pile on top of each other and come off in reverse order. LAST ON, FIRST OFF. The stack is scratch memory for functions. Function runs, it gets a slice (a frame) holding its local variables and its return address. Function ends, slice gone.&lt;/p&gt;

&lt;p&gt;Example: a notebook. You write top to bottom. One task per line.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Line 1: Doing taxes. When done, go back to the line where I left off.&lt;/li&gt;
&lt;li&gt;You hit a step that needs a sub-task, so you go to a new line.&lt;/li&gt;
&lt;li&gt;Line 2: Doing the math part of the taxes. When done, go back to line 1.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Each line is a function and also has its own work to do, plus a note that says which line to return to when done. When line 2 was finished, we went back to line 1. So what is the bug in our code? The note and the line sit side by side, so when the work in a line runs long and flows past it, it goes over to the note section and writes over the return note. Now the note points to the wrong line, and you jump somewhere you should not, and you crash, boom!&lt;/p&gt;

&lt;p&gt;So now listen, there is a safeguard there called a stack canary. A tripwire between your buffer and the return address that catches an overflow. If it's there, our attack won't work, so we remove it using &lt;code&gt;-fno-stack-protector&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;-f  -&amp;gt; gcc compiler features
-no -&amp;gt; means no! So it's saying no stack protector. So our attack can take place.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Also &lt;code&gt;-z execstack&lt;/code&gt; -&amp;gt; there are 2 things you can do in memory. Store stuff in it (data), and run stuff in it as instructions, like code. Normally the stack is allowed to store but not run code. It's locked, data only. The lock itself is the defense. &lt;code&gt;-z execstack&lt;/code&gt; unlocks that safety lock. Now the stack can run code too. So why do we care about this? Well, we can sneak our code into &lt;code&gt;buf&lt;/code&gt;, which lives on the stack memory, and then we can make the CPU jump onto it. If the stack is data-only, the CPU refuses to run code on it.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;-no-pie&lt;/code&gt; -&amp;gt; Position Independent Executable. Okay, now normally the OS loads our app in a random location in virtual memory every time it runs, which makes it much harder for attackers to exploit a buffer overflow or a predictable memory address. But when we put the flag &lt;code&gt;-no-pie&lt;/code&gt;, the application loads from a static address. Random position = hard to aim at. Fixed position = you can aim. That's why you turn it off for the lab.&lt;/p&gt;






&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;└─$ gcc server.c -o server -fno-stack-protector -z execstack -no-pie
server.c: In function ‘main’:
server.c:25:9: warning: ‘read’ writing 512 bytes into a region of size 64 overflows the destination [-Wstringop-overflow=]
   25 |         read(client, buf, 512); //  VULNERABILITY: Reads 512 bytes into a 64-byte buffer
      |         ^~~~~~~~~~~~~~~~~~~~~~
server.c:24:14: note: destination object ‘buf’ of size 64
   24 |         char buf[64];
      |              ^~~
In file included from server.c:3:
/usr/include/unistd.h:371:16: note: in a call to function ‘read’ declared with attribute ‘access (write_only, 2, 3)’
  371 | extern ssize_t read (int __fd, void *__buf, size_t __nbytes) __wur
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Gave us a big warning.&lt;/p&gt;

&lt;p&gt;After that, when I run &lt;code&gt;./server&lt;/code&gt; it's just sitting there waiting. It is waiting on a caller to reach out on port 31337. We can actually confirm it's listening.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;ss -tlnp | grep 31337

┌──(kali㉿kali)-[~/Desktop/Test]
&lt;/span&gt;&lt;span class="gp"&gt;└─$&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;ss &lt;span class="nt"&gt;-tlnp&lt;/span&gt; | &lt;span class="nb"&gt;grep &lt;/span&gt;31337
&lt;span class="go"&gt;LISTEN 0      1            0.0.0.0:31337      0.0.0.0:*    users:(("server",pid=647479,fd=3))
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Now comes the fun part: the FUZZER
&lt;/h2&gt;

&lt;p&gt;Scenario: connect to our server and send way more than 64 bytes to crash it, proving the overflow reaches the return address.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;

&lt;span class="c1"&gt;# Let's create a TCP / IP socket.
&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;SOCK_STREAM&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="c1"&gt;# Now we connect to the server itself.
&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;connect&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;127.0.0.1&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;31337&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;

&lt;span class="c1"&gt;# Now let's send some data. It must be bytes. 513 bytes to be exact!
&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;sendall&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;b&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;A&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="mi"&gt;513&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;  &lt;span class="c1"&gt;# Boom, because A is exactly one byte.
&lt;/span&gt;
&lt;span class="c1"&gt;# Clean up and close the connection.
&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;close&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Run it -&amp;gt; &lt;code&gt;python3 fuzz.py&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Here's the catch with &lt;code&gt;fuzz.py&lt;/code&gt;: when you run it, it won't actually crash, because the overflow smashed &lt;code&gt;main()&lt;/code&gt;'s return address, but that only matters when &lt;code&gt;main()&lt;/code&gt; ends. &lt;code&gt;main()&lt;/code&gt; never ends, so it loops forever to accept connections. So the smashed address just sits there unused. No use, no crash. And we do not want to end &lt;code&gt;main()&lt;/code&gt;, it needs to keep going to accept connections.&lt;/p&gt;




&lt;h2&gt;
  
  
  Let's Fix Our server.c Now
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;FIX:&lt;/strong&gt; put the vulnerable buffer in a small helper function that ends on every connection it makes, so &lt;code&gt;main()&lt;/code&gt; can keep running.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;PLAN:&lt;/strong&gt; make a handle function holding &lt;code&gt;buf&lt;/code&gt; and &lt;code&gt;read&lt;/code&gt;. &lt;code&gt;main()&lt;/code&gt;'s loop calls it, the handle function finishes after each connection, and only then does it read its smashed return note and crash.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;stdio.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;      // Stands for input and output - printf()&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;string.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;     // String and memory functions&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;unistd.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;     // Gives you the raw system calls like -&amp;gt; read(), write(), and close()&lt;/span&gt;&lt;span class="cp"&gt;
#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;arpa/inet.h&amp;gt;&lt;/span&gt;&lt;span class="c1"&gt;  // Gives you network address tools -&amp;gt; htons(), which flips your port number into the byte order the network expects.&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;
&lt;span class="c1"&gt;// This function handles the connection and holds the vulnerable buffer overflow logic.&lt;/span&gt;
&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;handle_connection&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;client_sock&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;
    &lt;span class="c1"&gt;// void -&amp;gt; this function hands nothing back when it finishes.&lt;/span&gt;
    &lt;span class="c1"&gt;// client_sock -&amp;gt; the client's network channel.&lt;/span&gt;
    &lt;span class="c1"&gt;// A char is one byte and we created a box holding 64 bytes.&lt;/span&gt;
    &lt;span class="c1"&gt;// Now we can't really put 512 bytes in the box; it will overflow.&lt;/span&gt;
    &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;64&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
    &lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client_sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;512&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;  &lt;span class="c1"&gt;// VULNERABILITY: Reads 512 bytes into a 64-byte buffer&lt;/span&gt;
    &lt;span class="n"&gt;printf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"Processed connection data.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;(){&lt;/span&gt;
    &lt;span class="c1"&gt;// Socket is basically the network channel&lt;/span&gt;
    &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;sock&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;SOCK_STREAM&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="c1"&gt;// 0 is for accepting the default transport protocol, which is TCP.&lt;/span&gt;
    &lt;span class="c1"&gt;// htons just takes the port and converts it into a byte order that the network understands.&lt;/span&gt;
    &lt;span class="c1"&gt;// sockaddress is the address for the network channel&lt;/span&gt;
    &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;sockaddr_in&lt;/span&gt; &lt;span class="n"&gt;Sockaddress&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;htons&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;31337&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;}};&lt;/span&gt; &lt;span class="c1"&gt;// 0 is open, meaning listen on all my machine's IPs, not just one.&lt;/span&gt;
    &lt;span class="c1"&gt;// Bind = attach the address to the network channel.&lt;/span&gt;
    &lt;span class="c1"&gt;// sock is of course the socket network channel and we are binding it with the socket address.&lt;/span&gt;
    &lt;span class="c1"&gt;// (struct sockaddr*) is a generic label bind accepts; the * makes it -&amp;gt; pointer to.&lt;/span&gt;
    &lt;span class="c1"&gt;// &amp;amp;Sockaddress is the actual pointer to the sockaddr_in box we made earlier.&lt;/span&gt;
    &lt;span class="n"&gt;bind&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="n"&gt;sockaddr&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;Sockaddress&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Sockaddress&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
    &lt;span class="n"&gt;listen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;  &lt;span class="c1"&gt;// Start accepting incoming connections on the socket &amp;amp; 1 = how many callers can wait on hold while you're busy with one.&lt;/span&gt;
    &lt;span class="k"&gt;while&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;accept&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;))){&lt;/span&gt;
        &lt;span class="c1"&gt;// Remember we are the caller!&lt;/span&gt;
        &lt;span class="c1"&gt;// client is whoever connects to your network channel. The first 0 is the caller's info or address, so we will not log that, and since the caller is us and we are on localhost there is no point saving that. The second 0 -&amp;gt; do not save the size of the IP address either.&lt;/span&gt;

        &lt;span class="c1"&gt;// Let's call the handle_connection function.&lt;/span&gt;
        &lt;span class="n"&gt;handle_connection&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

        &lt;span class="n"&gt;close&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now recompile it -&amp;gt; &lt;code&gt;gcc server.c -o server -fno-stack-protector -z execstack -no-pie&lt;/code&gt; -&amp;gt; then run &lt;code&gt;python3 fuzz.py&lt;/code&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;13&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="n"&gt;warning&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="err"&gt;‘&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="err"&gt;’&lt;/span&gt; &lt;span class="n"&gt;writing&lt;/span&gt; &lt;span class="mi"&gt;512&lt;/span&gt; &lt;span class="n"&gt;bytes&lt;/span&gt; &lt;span class="n"&gt;into&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;region&lt;/span&gt; &lt;span class="n"&gt;of&lt;/span&gt; &lt;span class="n"&gt;size&lt;/span&gt; &lt;span class="mi"&gt;64&lt;/span&gt; &lt;span class="n"&gt;overflows&lt;/span&gt; &lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;destination&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;Wstringop&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;overflow&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
   &lt;span class="mi"&gt;13&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt;     &lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client_sock&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;512&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;  &lt;span class="c1"&gt;//  VULNERABILITY: Reads 512 bytes into a 64-byte buffer&lt;/span&gt;
      &lt;span class="o"&gt;|&lt;/span&gt;     &lt;span class="o"&gt;^~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/span&gt;
&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;12&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="n"&gt;note&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="n"&gt;destination&lt;/span&gt; &lt;span class="n"&gt;object&lt;/span&gt; &lt;span class="err"&gt;‘&lt;/span&gt;&lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="err"&gt;’&lt;/span&gt; &lt;span class="n"&gt;of&lt;/span&gt; &lt;span class="n"&gt;size&lt;/span&gt; &lt;span class="mi"&gt;64&lt;/span&gt;
   &lt;span class="mi"&gt;12&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt;     &lt;span class="kt"&gt;char&lt;/span&gt; &lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;64&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
      &lt;span class="o"&gt;|&lt;/span&gt;          &lt;span class="o"&gt;^~~&lt;/span&gt;
&lt;span class="n"&gt;In&lt;/span&gt; &lt;span class="n"&gt;file&lt;/span&gt; &lt;span class="n"&gt;included&lt;/span&gt; &lt;span class="n"&gt;from&lt;/span&gt; &lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;usr&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;include&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;unistd&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;h&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;371&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;16&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="n"&gt;note&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="n"&gt;in&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;call&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;function&lt;/span&gt; &lt;span class="err"&gt;‘&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="err"&gt;’&lt;/span&gt; &lt;span class="n"&gt;declared&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;attribute&lt;/span&gt; &lt;span class="err"&gt;‘&lt;/span&gt;&lt;span class="n"&gt;access&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;write_only&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="err"&gt;’&lt;/span&gt;
  &lt;span class="mi"&gt;371&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="k"&gt;extern&lt;/span&gt; &lt;span class="kt"&gt;ssize_t&lt;/span&gt; &lt;span class="n"&gt;read&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;__fd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;__buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;size_t&lt;/span&gt; &lt;span class="n"&gt;__nbytes&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;__wur&lt;/span&gt;
      &lt;span class="o"&gt;|&lt;/span&gt;                &lt;span class="o"&gt;^~~~&lt;/span&gt;
&lt;span class="n"&gt;Processed&lt;/span&gt; &lt;span class="n"&gt;connection&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;
&lt;span class="n"&gt;zsh&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="n"&gt;segmentation&lt;/span&gt; &lt;span class="n"&gt;fault&lt;/span&gt;  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;We will learn more, but our buffer overflow worked!&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>programming</category>
      <category>security</category>
    </item>
  </channel>
</rss>
