挖掘linux系统程序里栈溢出的程序

//挖掘linux系统程序里栈溢出的程序
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <errno.h>
#include <sys/mman.h>
#include <sys/wait.h>
#include <signal.h>



int main(int argc, char *argv[])
{
        int fd;
        int *p;
        int i;
        int ret;
        pid_t pid;
        char buf[1024];
        char *addr;
        int count = 0;
        int status;
        fd = open("linux.txt", O_RDWR);
        if(fd < 0)
        {
                perror("open");
                exit(1);
        }
        addr = (char *)mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_SHARED, fd, 0);
        if(addr == MAP_FAILED)
        {
                perror("mmap");
                exit(1);
        }
        close(fd);
        while(1)
        {
                count++;
                printf("count = %d\n", count);
                memset(buf, 0, sizeof(buf));
                strcpy(buf, addr);
                sprintf(buf, "linux-%d", count);
                printf("buf = %s\n", buf);
                sleep(1);
                if(count == 10)
                {
                        break;
                }
                if(count == 5)
                {
                        pid = fork();
                        if(pid < 0)
                        {
                                perror("fork");
                                exit(1);
                        }
                        if(pid == 0)
                        {
                                while(1)
                                {
                                        sleep(1);
                                        printf("child\n");
                                        if(count == 10)
                                        {
                                                break;
                                        }
                                        count++;
                                        printf("count = %d\n", count);
                                        memset(buf, 0, sizeof(buf));
                                        strcpy(buf, addr);
                                        sprintf(buf, "linux-%d", count);
                                        printf("buf = %s\n", buf);
                                        sleep(1);
                                        if(count == 10)
                                        {
                                                break;
                                                exit(0);
                                        }
                                        if(count == 5)
                                        {
                                                break;
                                                exit(0);
                                        }
                                        if(count == 6)
                                        {
                                                break;
                                                exit(0);
                                        }
                                        if(count == 7)
                                        {
                                                break;
                                                exit(0);
                                        }
                                        if(count == 8)
                                        {
                                                break;
                                                exit(0);
                                        }
                                        if(count == 9)
                                        {
                                                break;
                                                exit(0);
                                        }


                                }
                                exit(0);
                        }
                        else
                        {
                                while(1)
                                {
                                        sleep(1);
                                        printf("parent\n");
                                        if(count == 10)
                                        {
                                                break;
                                                exit(0);
                                                wait(&status);
                                                if(WIFEXITED(status))
                                                {
                                                        printf("child exit code = %d\n", WEXITSTATUS(status));
                                                        exit(0);
                                                        wait(&status);
                                                        if(WIFEXITED(status))
                                                        {
                                                                printf("child exit code = %d\n", WEXITSTATUS(status));
                                                                exit(0);
                                                                wait(&status);
                                                                if(WIFEXITED(status))
                                                                {
                                                                        printf("child exit code = %d\n", WEXITSTATUS(status));
                                                                        exit(0);
                                                                        wait(&status);
                                                                        if(WIFEXITED(status))
                                                                        {
                                                                                printf("child exit code = %d\n", WEXITSTATUS(status));
                                                                                exit(0);
                                                                                wait(&status);
                                                                                if(WIFEXITED(status))
                                                                                {
                                                                                        printf("child exit code = %d\n", WEXITSTATUS(status));
                                                                                        exit(0);
                                                                                        wait(&status);
                                                                                        if(WIFEXITED(status))
                                                                                        {
                                                                                                printf("child exit code = %d\n", WEXITSTATUS(status));
                                                                                                exit(0);
                                                                                                wait(&status);
                                                                                                if(WIFEXITED(status))
                                                                                                {
                                                                                                        printf("child exit code = %d\n", WEXITSTATUS(status));
                                                                                                        exit(0);
                                                                                                        wait(&status);
                                                                                                        if(WIFEXITED(status))
                                                                                                        {
                                                                                                                printf("child exit code = %d\n", WEXITSTATUS(status));
                                                                                                                exit(0);
                                                                                                                wait(&status);
                                                                                                        }
                                                                                                }
                                                                                        }
                                                                                }
                                                                        }
                                                                }
                                                        }
                                                }
                                        }
                                }
                        }
                }                                                                        
        } 
}

  • 3
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值