How to look at the stack with gdb
jvns.ca
jvns.ca
- you’re on 64-bit, so you probably want x/gx (or x/16gx, etc.) to print out 64-bit words (the g means “giant”). That’ll make the addresses on the stack more useful. (x/ax works too, and will attempt to resolve addresses to symbols if possible, at the cost of making the output not aligned in columns).
- the stack overflow is detected by using a canary value, basically a random series of bytes sitting after the string on the stack (your canary for example is 0x00 0x80 0xf7 0x8a 0x8a 0xbb 0x58 0xb6). This gets checked at the end of the function; on a mismatch, the function calls __stack_chk_fail which prints an error and aborts the program. The canary is pretty clever: it starts with a null byte so that it won’t be leaked by normal string functions, and the true canary is stored somewhere else in memory (not th stack) so it can’t be easily leaked or corrupted.
Doesn't that also mean it won't be overwritten by string functions, masking certain bugs? Would it be better to make the nul byte the second one, so that only one byte can be leaked, but certain program bugs that wouldn't otherwise will be exposed?
Specifically, on x86-64 Linux it's stored at fs:0x28.
If you think there are any ways we can improve, please don't hesitate to create an Issue on Github for new features or bug fixes.
https://github.com/pwndbg/pwndbg/blob/dev/caps/disasm_taken_...
This also works for stepping through e.g. ROP gadgets during exploitation.
I really like it. I find it simple in the same way I find C a simple language. There isn't that many commands that you use frequently and the names are quite intuitive and can be shortened to a single letter if there are no conflicts. Now, on Windows, WinDbg I never really groked. I found it hard to use.
the vscode remote ssh extension has you covered.
See windbg also.
Debugging such condition would be ... unsafe.
ja ja.