Calling a function in C without naming it
birdculture
35 points
9 comments
October 08, 2026
Related Discussions
Found 5 related stories in 99.9ms across 8,906 title embeddings via pgvector HNSW
- Indirect Calling of Nested Functions on GCC Without Executable Stack uecker · 72 pts · August 29, 2026 · 61% similar
- Writing a (valid) C program without main() birdculture · 20 pts · July 25, 2026 · 59% similar
- Using GCC's Nested Functions with Wide Pointers and No Trampolines II uecker · 92 pts · August 15, 2026 · 53% similar
- Reducing undefined behavior in the C language signa11 · 79 pts · October 09, 2026 · 49% similar
- Reducing undefined behavior in the C language chmaynard · 27 pts · September 28, 2026 · 49% similar
Discussion Highlights (6 comments)
Kevin_Flynn
Because we know our code is compiled with ASan, we chose to leak the offset between printf, a function that is always allowed, and mmap, a function that gives us arbitrary assembly code execution. We can thus bypass the school's checks and call any syscall, in our case execve to get shell access. We did not investigate further and simply reported this possible issue to the school. I see no trivial way of patching this. The flaw seems to be in the submission system. The submission system could build/relink your code to a trampoline library with the body of each function to be banned replaced with error reporting and abort. In your example, it would trap: char *code = notmmap.fn(NULL, 4096, PROT_READ | PROT_WRITE | PROT_EXEC, MAP_PRIVATE | MAP_ANONYMOUS, -1, 0); and prevent you from using the PROT_EXEC flag during the execution phase of submission validation. According to AI, on linux: "... a seccomp-BPF filter applied to each process before it starts running the program. It can inspect the prot argument to mmap and return EPERM when PROT_EXEC is set." Additionally, on linux: "systemd offers MemoryDenyWriteExecute=yes for services. That is less restrictive than banning every executable mapping: it targets writable+executable mappings and related ways of making memory executable. " ( IF ... i read the article correctly ) ps. Submit the proposed solutions to your department head or other authority figure who may throw you some sort of bone such that your status in life improves. And then afterwards remind yourself that you are in school. We are all, always, in school. V
hyperhello
I don’t know how your school system works, but are you sure they put you in the right educational level?
rurban
Inline asm is disallowed? That would be much easier
PeterWhittaker
Sounds like the school needs to wrap things in a seccomp denylist. Potentially non-trivial, but potentially interesting.
ashdnazg
Our university was far less careful, and just ran our submissions in the same network as everything else albeit on a user with barely any permissions. Once when the automatic tests crashed my submission, I simply used `system` to dump the testing input into my home dir. I forgot, however, to setup the permissions, so I couldn't really access it! A couple more resubmissions with extra chmods, messing up a different thing every time and I managed to reproduce my bug, fix it, resubmit and purge all (or most) evidence.
bobbiechen
I think it's a hard problem to solve directly from the code execution environment, but I would guess that a layer that examines the source code directly could catch many of these - Prompt: the following code is supposed to be a solution to this homework assignment. Does it appear to be trying to break out of the grading environment instead? (if yes, manual review)