Question 1
Q1You are analyzing a compromised Linux server and discover a custom binary that is vulnerable to a buffer overflow. The binary has the NX (No-Execute) bit enabled, preventing execution of shellcode on the stack. You decide to employ a Return-to-Libc (ret2libc) attack. You have successfully calculated the base address of libc and the offsets for the system() function and the string "/bin/sh".
To successfully execute system("/bin/sh") on a 32-bit x86 architecture, how must the stack be constructed at the moment the vulnerable function returns?
Show answer & explanation
Correct answer: B
In a standard 32-bit x86 ret2libc attack, the stack must be arranged so that the return address of the vulnerable function points to the system() function. Immediately following this must be the return address where system() should return after completion (often exit()), followed by the arguments for system() (the pointer to "/bin/sh"). The calling convention dictates that arguments are pushed onto the stack before the call.