3 ms·
It uses the __readonly_area glibc function which actually parses /proc/self/maps: https://code.woboq.org/userspace/glibc/sysdeps/unix/sysv/linux/readonly-area.
by hoytech 6y ago
It uses the __readonly_area glibc function which actually parses /proc/self/maps:
https://code.woboq.org/userspace/glibc/sysdeps/unix/sysv/linux/readonly-area.c.html#__readonly_area https://code.woboq.org/userspace/glibc/sysdeps/unix/sysv/lin...
So no, I don't believe it will prevent using "%n" in memory that you have made writable. But this isn't really an issue because typically a format string exploit would have no way to arbitrarily call mprotect.
That said, there are other ways to abuse format string bugs apart from %n, for example "Direct Parameter Access" to get stack cookies, and the like:
https://cs155.stanford.edu/papers/formatstring-1.2.pdf https://cs155.stanford.edu/papers/formatstring-1.2.pdf