Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Herramientas/GitHubGitHub/anna-kravets/codeql-buffer-overflow-variant
Static AnalysisStatic Code Analysis (SAST)Vulnerability AnalysisCode Analysis
GitHubanna-kravets/codeql-buffer-overflow-variant

codeql-buffer-overflow-variant

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
6hace 10 díasAún no revisado
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

codeql-buffer-overflow-variant

A deliberately vulnerable, ~170-line C program used as a CodeQL static-analysis target. It reproduces the bug class of CVE-2020-8597 — the pppd EAP rhostname stack buffer overflow (CWE-120) — in a program that shares none of pppd's function names, call depth, or dispatch structure.

The goal is a generality test: a CodeQL query written to catch the pppd bug must also fire on this program, unedited. If it does, the query expresses the bug class rather than the original code's shape.

This program is intentionally unsafe and exists only for analysis. Do not deploy it. The bug it mirrors is public (CVE-2020-8597, disclosed 2020).

The bug class

An attacker-derived length is copied into a fixed-size buffer, with no guard relating that length to the buffer's size.

In every case a bounds check is present — it just fails to relate the two quantities that matter. There are exactly two ways to get that wrong, and the program contains one of each:

  • Right value, wrong bound. The copy length is checked, but against the received frame instead of sizeof(dest). Prevents an over-read, does nothing about the over-write. ()
handle_hello
  • Right bound, wrong value. The check names sizeof(dest) — it looks exactly like a buffer bound — but constrains a different variable than the one used as the copy length. (handle_stat)
  • The second is the harder one, and it is what pppd's dead vallen >= len + sizeof(rhostname) check is: a comparison that mentions the destination size while constraining something that is not the copy length. A query that only asks "does some comparison here mention sizeof(dest)?" is silenced by it.

    Structure vs. pppd (why it's a real variant)

    pppd / CVE-2020-8597this project
    Sourceread() on the PPP fdrecvfrom() on a UDP socket
    Dispatchglobal struct protent *protocols[], linear match on protocol no.file-local const struct frame_op ops[], linear match on 1-byte tag
    Depth to sinkget_input → (*input) → eap_input → eap_requestdispatch_frame → (*handle) → handle_hello
    Destinationchar rhostname[256]char name[64]
    Wrong guardvallen bounded by packet lenvlen bounded by frame plen

    Both keep the one property that makes this data-flow, not grep: an indirect call through a function-pointer table between the source and the sink.

    HandlerLineCheck presentVerdict
    handle_hello()sink at :80vlen > plen - 2 — right value, wrong boundmust fire
    handle_echo()copy at :106vlen >= sizeof(buf) — both rightmust stay silent — negative control
    handle_stat()sink at :145hlen >= sizeof(report) — right bound, wrong valuemust fire

    handle_stat is the discriminating case. Its check names sizeof(report), so a query that accepts any comparison mentioning the destination size treats it as guarded and misses the bug. Catching it requires comparing the value being checked against the value used as the copy length — global value numbering. Delete that from the query and this handler becomes a false negative while every other site keeps its verdict.

    Wire format

    One UDP datagram = one frame:

    root@kitploit:~
    [ type : 1 ] [ length : 2, big-endian ] [ value : length bytes ]
    

    type 0x01 → hello, 0x02 → echo, 0x03 → stat. A hello frame with a declared length between 65 and ~2045 overflows name[64]. A stat frame carries two one-byte lengths instead — a header length and a body length — and any body length above 32 overflows report[32], whatever the header length says.

    Build

    root@kitploit:~
    make            # gcc -Wall -Wextra -O0 -g -o tlv_server tlv_server.c
    

    Linux/POSIX (BSD sockets). Builds clean with no warnings.

    Build a CodeQL database

    CodeQL traces a real compile, so build from clean:

    root@kitploit:~
    make clean
    codeql database create db --language=cpp --command="make"
    # or, without the clean step:
    codeql database create db --language=cpp --command="make -B"
    

    Then run the Part 3 query against db; it should report the memcpy in handle_hello and the one in handle_stat, and stay silent on handle_echo. The query and its run instructions live in codeql/.

    The source changes whenever a handler is added, so rebuild the database — CodeQL snapshots the code at database create time and an existing db/ will not see new code.

    Descargar herramienta