5 ms·
Useless semantic pedantry at best, but arguable wrong as there isn't some sort of ISO standard on dumb hacking terms.
by rhexs 4y ago
Useless semantic pedantry at best, but arguable wrong as there isn't some sort of ISO standard on dumb hacking terms.
- saagarjha 4y agoOverflowing the stack gives you a segfault. Smashing the stack lets hackers pop a shell on your computer. They are incredibly different. VLAs can crash your program, but they do not give attackers the ability to scribble all over the stack.
- pjmlp 4y agoUnless they happen to be enjoying kernel space.
- saagarjha 4y agoThere is no difference.
- bjourne 4y ago> Overflowing the stack gives you a segfault. Maybe. If the architecture supports protected memory and the compiler has placed an appropriately sized guard page below the stack. If it doesn't then overflowing the stack via a VLA gives you easy read and write access to any byte in program memory.
- saagarjha 4y agoIf your architecture does not support this then you’re at risk whenever you make a function call.
- rhexs 4y agoBackpedal harder!
- saagarjha 4y agoI’m not backpedaling. If your environment has guard pages and does probing then it protects equally well against VLAs and function calls overflowing the stack. If it has neither then both are liable to overwrite other memory. Obviously I would prefer that you have the protections, or some sort of equivalent, but they have nothing to do with VLAs.