Writing Behind a Buffer
Angelo Rosiello, Rosiello Security · 2005
In this paper we are going to describe a kind of vulnerability that is known in the literature but also poor documented. In fact, the problem that is going to be analyzed can be reduced to a memory adjacent overwriting attack but usually it is obtained exploiting the last null byte of a buffer, hence we are going to show that the same result is still possible writing behind a buffer, under certain conditions. To fully understand the subject of this article it's necessary to describe the memory organization1 of running processes, then the memory adjacent overwrite attack, concluding with our analysis. Memory Organization A process can be defined as a running program, thus the operating system has loaded its instructions into memory and has allocated different areas of memory to manage its execution. The address space of a running process can be divided into five segments[1,2]: • Code Segment: this segment contains the executable code of the program. • Data and BSS Segment: both sectors are dedicated to the global variables and are allocated during the compile time. To be clear, the sector BSS contains not initialized data while data segment is reserved for static data. • Stack Segment: local variables are allocated in this segment. It is particular useful for storing cotext and for function parameters. The stack memory grows downward. • Heap Segment: this segment represents all the rest of memory of the process. The heap memory grows upward and is allocated dynamically. In figure 1 we can observe all the memory segments described above.