15–25 min Updated

Buffer Overflows

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

An attacker can use buffer overflows to take your site offline or to inject malicious code.

Prevalence
Rare
Exploitability
Moderate
Impact
Devastating

What is a buffer overflow?

A buffer overflow is a memory corruption vulnerability in which a program writes more data into a fixed-length block of memory than it can hold, overwriting adjacent memory. Attackers exploit it by sending oversized input to crash a server or to execute malicious code. It mostly affects software written in languages without bounds checking, such as C and C++.

What you'll learn

  • How writing past the end of a buffer corrupts neighboring memory
  • How attackers use no-op instructions to get injected code executed
  • Why prompt patching and memory-managed languages limit your exposure

Where this lesson counts

PCI DSS v4.0.1

  • Buffer Overflows lab

    Type an over-long username into a small C program that never checks input length and watch it crash with a segmentation fault. Then see how overflowing data spills into neighboring memory, and how attackers use a run of no-op instructions to get their own code executed.

  • How to prevent Buffer Overflows

    The prevention guide covers five approaches, including:

    • Automate Your Build and Deployment Process
    • Keep on Top of Security Bulletins
    • Deploy Security Patches as Soon as They Become Available
  • Buffer Overflows quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Remote Code Execution

    If an attacker can smuggle code into your web-server process, you have a serious problem.

  • Denial of Service Attacks

    Sometimes attackers don't need to hack your website, they just want to make it unavailable to others.

  • Command Execution

    If your application calls out to the OS, you need to be sure command strings are securely constructed.