hn.today

Calling a function in C without naming it

wiro.world21 points4 comments
Screenshot of Calling a function in C without naming it

A controlled remote grading environment prevented naming disallowed functions like execve by checking the compiled code’s AST, so the goal was to call execve without referencing its symbol. The exploit relies on the fact that ASLR randomizes segment base addresses but preserves fixed offsets between functions inside the same shared object. By leaking a known offset on the target between an allowed symbol and a target libc symbol, the exploit computes the runtime address of mmap (and by extension execve/syscalls). Because the build uses ASan, many common functions are replaced and live in different segments, so the author picked symbols that remain in the libc segment and used unions to mutate function-pointer representations without triggering pedantic compiler casts.

With the computed mmap address they allocate a writable, executable page, copy a small syscall trampoline into it (a few x86-64 instructions that move arguments into registers and issue syscall), and invoke that trampoline as a function to perform syscall 59 (execve) and spawn a shell. The proof-of-concept uses leaked offsets, union-based pointer manipulation, and a hand-crafted syscall stub to bypass the grader’s checks; the author reported the issue and notes mitigation is nontrivial (e.g., relinking libc with randomized symbol order), while ASan replacements complicate defenses.

Read on wiro.world4 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.