ContraPolice: a libc Extension for Protecting Applications from Heap-Smashing Attacks

Andreas Krennmair · 2003

In today’s computer security, buffer overflows are a huge problem – most of the time caused by inexperienced programmers using inadequate language without fully understanding all consequences of using. One of these languages that cause such problems ist C, an imperative programming language developed in the early 1970s by Dennis Ritchie. Unfortunately, at this time hardly anybody of the big problems that insecure buffer handling could cause. This led to a set of insecure library functions in the first versions of the C standard library that eventually got standardized together with the C language and that are still widely used by inexperienced C programmers – and even by their teachers, since that was the way they learned it themselves. And to keep up backward compatibility, even new versions of the C standard (i.e. C99) still contain these insecure functions. The fundamental problem of buffer overflows is that memory is “accidently” being overwritten that is interpreted as e.g. a function pointer or return address inside the program. The cause is that programmers often enough don’t really care about input validation, including input length. Programmers still use insecure functions like

Read the paper · More papers on PaperTik