Skip to content
EN

Back to the catalog

ankithooda.com
rss2English

Ankit Hooda's Blog

ankithooda.com · English

rss2 wordpress content media slash wfw atom dc sy

Open the feed

https://ankithooda.com/feed/

Last post
Nov 22, 2024
Posts in 24 h · 7 days · 30 days
0 · 0 · 0
Our last check
Answering
Served from
United States
Text score at discovery
15,284
Format
rss2
Features in the feed
content, media, slash, wfw, atom, dc, sy
Community
wordpress

Posts

What our queue read from this feed. Open one to read it here, or go to the site that published it.

  1. Return-Oriented Programming
    Nov 22, 2024 · original
    In a previous post , I described how to inject code to execute syscall by overwriting the stack. To summarize the previous post – Use a bug in the code to overwrite the return address stored on stack. This is mitigated by Stack Smashing Protector where compiler adds additional code to check the integrity of stack. Store the exploit (code + data) on stack and then point the return address to the starting of the exploit code. When the program executes the RET instruction it will execute the exploit code instead of returning to the calling function. To mitigate this Enable ASLR which randomizes stack and other locations on every run so that we can not determine the starting address of our exploit code stored on the stack. Enable Non-Executable Stack, so that trying to execute code stored on stack will result in a Segmentation Fault. ROP (Return Oriented Programming) is a technique which can
  2. Code Injection via Stack Overflow
    Nov 10, 2024 · original
    I will use the simplest code sample which allows a stack overflow attack to happen. #include stdio.h void print_exploit_message() { printf("Congrats, Exploit\n"); } void read_from_input(){ char buf[10]; gets(buf); return; } int main() { read_from_input(); printf("No Exploit\n"); } The code snippet does the following things Allocate a 10 byte buffer on the stack. Uses gets function to receive input from STDIN and copy into the buffer, Copying is done by the gets function and it does not check size of input and size of buffer, so it can overwrite the data received in input past the bounds of buffer. Print a string and exit. There is also an additional function which is defined but not called. Mitigations Before I explain the actual attack, let’s first discuss the various techniques that are employed by compilers and operating systems to prevent this type of attack. I will disable these mit
  3. Rendering fonts in bootloader
    Aug 5, 2024 · original
    I have used Bare bones setup described by OSDev to jump into the Long Mode and run a small C program. The bare bones setup initializes a graphical device and provides a framebuffer for manipulating the device i.e we can print anything by setting bits to turn on/off the pixels in the device. The above text and numbers have been printed using the Spleen Font . Each character is 16×32 pixels in size, there are 32 rows of 16 pixels each. Whether the pixel is on/off is described by 64 bytes of data (2 bytes for each row). We declare an array of 8192 uint16_t elements. There are a total of 256 values possible in a 8 bit ASCII code of which only a few are printable. To keep the rendering logic simple, we will load the data for all 256 possible character, unprintable characters are printed as a white box i.e all 16×32 pixels are on. This is how all 256 chars look like. The terminal is represente
  4. Notes on Hardware and Software Support for Virtualization – Part 2
    Jul 25, 2024 · original
    The Popek/Goldberg Theorem Introduced in a paper in 1974, Can be used to determine whether a given ISA can be virtualized by a VMM using multiplexing. For any ISA meeting the hypothesis, any OS that can run directly on the hardware can also run on VMM written for that ISA. Original intent was to prove that newer architecuture (i.e new according to year 1974) broke virtualization ex – DEC PDP-11 Theorem remains fundamental because it shows the relation between hardware and it’s ability to support virtual machines. Model Theorem assumes a conventional third generation architecutre – Processor has two execution modes supervisor and user mode Virtual memory is implemented using segmentation Physical memory is contiguous and total size is available at reset time Processor system state – called PSW (Processor State Word) is a tuple (M, B, L, PC) Mode – supervisor or user B, L – Base and Length
  5. Notes on Hardware and Software Support for Virtualization – Part 1
    Jul 22, 2024 · original
    These are the notes of the book – Hardware and Software Support for Virtualization by Bugnion, Nieh, Tsafrir (Synthesis Lectures on Computer Architecture) Historical Perspective Hardware support for virtualization on x86 was introduced in early 2000s Before that virtualization solution like VMware, Disco, Xen used workarounds the hardware. this book’s focus is on what hardware/software support is required for virtualization Three techniques are used in virtualization. Multiplexing - Operating System’s scheduler, multiplexes a physical CPU across time and uses this to provide an abstraction called process to the users. Aggregation - RAID, aggregates multiple disks and exposes a single disk to users. Emulation - MMU is used to emulate a virtual memory which behaves like physical memory, User programs use virtual address as if they are physical addresses. One processor emulating another, a
  6. xv6 Hacking : NULL Pointer Dereference
    Mar 4, 2024 · original
    xv6 loads the userspace program starting from the virtual address 0x0, which means we can dereference a null pointer in a xv6 process and it will be a valid memory access. #include "types.h" #include "user.h" #include "stat.h" int main(int argc , char **argv) { int *c = (int *)0x0; printf(1, "%d\n", *c); exit(); } Compiling and running the above program, xv6 kernel throws an illegal opcode error. If we look at the assembly for the test_defp binary, we see that gcc has generated a ud2 (an undefined instruction in x86) in order to avoid NULL dereference. After adding the flag -fno-delete-null-pointer-checks the program compiles correctly and we are able to read the memory contents at 0x0 location. To make 0x0 an invalid address in xv6 userspace program, we can load the xv6 user programs at the next page boundary i.e 0x1000 instead of 0x0. To do that we need to understand how xv6 loads and
  7. xv6 Hacking : Virtual Memory
    Feb 21, 2024 · original
    We can solve any problem by introducing an extra level of indirection. – David J. Wheeler Consider the following user-space program, which makes a system call getpinfo . #include "types.h" #include "user.h" #include "pstat.h" int main(int argc, char *argv[]) { struct pstat p; getpinfo(&p); exit(); } getpinfo is a syscall which accepts pointer to a struct, it will populate the struct with some attributes of all running processes (kind of a ps command). Below code snippet shows the kernel code where this copying happens. ptable in the code below is a kernel data structure. void copypinfo(struct pstat *dest) { for (int i = 0; i NPROC; i++) { dest-inuse[i] = ptable.stat.inuse[i]; dest-pid[i] = ptable.stat.pid[i]; dest-tickets[i] = ptable.stat.tickets[i]; dest-ticks[i] = ptable.stat.ticks[i]; } } Two observations about the above snippet The struct dest was allocated on the heap of the userspa
  8. MySQL/MariaDB Hack Week
    Jan 10, 2024 · original
    During the MySQL/MariaDB Internals hack week , I worked on adding the following feature in MariaDB. MDEV-32854 : Make JSON_DEPTH_LIMIT Configurable JSON DataType in MariaDB In MariaDB, JSON data type is implemented as an alias of LONGTEXT Data type which can hold 4GB of text. For the JSON Datatype MariaDB validates the JSON string before storing it into the LONGTEXT column. The current validation logic has a hard-coded value of 32 as the maximum level of nesting that a JSON object can have. The feature request was to make this limit configurable through a system variable. Source Link Adding a new System Variable For this feature, I decided to add a global system variable ( instead of a session system variable, more details about the difference is here ). Because it is highly unlikely that users will want to have different values of JSON depth limit for different sessions. A new System Va
  9. Working with Spark UDAF in Java
    Sep 7, 2017 · original
    Spark comes with several in-built aggregation functions however if those do not satisfy the use case than writing your own User Defined Aggregation Function (UDAF for short) is simpler and cleaner way. In this post, I will be describing how to implement a Spark UDAF to compute harmonic mean using Java. UDAFs in spark are created by extending the UserDefinedAggregationFunction class present in the package org.apache.spark.sql.expressions . This class has seven abstract methods that are overridden when implementing a UDAF. The code snippets below describe each method and its implementation for the harmonic mean. // This method describes the schema of input to the UDAF. Spark UDAFs can be // defined to operate on any number of columns. Since, we are implementing the // the UDAF for Harmonic Mean which require only one value as input. public StructType inputSchema() { ListStructField inputFi

Discovered by the rss-feed-index crawler, which checks each feed at most once a month.

Same record as JSON: https://api.agentalog.com/api/feeds/fd_ankithooda_com_93393bf574df50fd. More from this site: ankithooda.com in the Feeds tab.