Buffer Overflows
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
An attacker can use buffer overflows to take your site offline or to inject malicious code.
- Prevalence
- Rare
- Exploitability
- Moderate
- Impact
- Devastating
What is a buffer overflow?
A buffer overflow is a memory corruption vulnerability in which a program writes more data into a fixed-length block of memory than it can hold, overwriting adjacent memory. Attackers exploit it by sending oversized input to crash a server or to execute malicious code. It mostly affects software written in languages without bounds checking, such as C and C++.
What you'll learn
- How writing past the end of a buffer corrupts neighboring memory
- How attackers use no-op instructions to get injected code executed
- Why prompt patching and memory-managed languages limit your exposure
Where this lesson counts
PCI DSS v4.0.1
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Buffer manipulation is the data-structure attack named explicitly in requirement 6.2.4.
Learn more about 6.2.4This lesson includes
Buffer Overflows lab
Type an over-long username into a small C program that never checks input length and watch it crash with a segmentation fault. Then see how overflowing data spills into neighboring memory, and how attackers use a run of no-op instructions to get their own code executed.
How to prevent Buffer Overflows
The prevention guide covers five approaches, including:
- Automate Your Build and Deployment Process
- Keep on Top of Security Bulletins
- Deploy Security Patches as Soon as They Become Available
Buffer Overflows quiz
Three questions. Passing marks the lesson complete.
Sources
- What is buffer overflow? Cloudflare
- Buffer Overflow Vulnerabilities Acunetix
- Buffer Overflow Attack OWASP
Related lessons
Browse all 45 lessons
Remote Code Execution
If an attacker can smuggle code into your web-server process, you have a serious problem.
Denial of Service Attacks
Sometimes attackers don't need to hack your website, they just want to make it unavailable to others.
Command Execution
If your application calls out to the OS, you need to be sure command strings are securely constructed.