DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Calling a function in C without naming it

Quality: 8/10 Relevance: 9/10

Summary

Two researchers describe bypassing a controlled remote code execution grading system in C to obtain arbitrary shell access by leaking memory offsets between allowable functions (printf) and executable functions (execve), constructing a small in-memory syscall trampoline, and using ASan and ASLR interactions to bypass checks. The article includes a PoC and discusses potential mitigations and security implications for similar educational environments.

🚀 Service construit par Johan Denoyer