Master the fundamental concepts of binary exploitation through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksAddressSanitizer is a fast memory error detector for C/C++ built into GCC and Clang. It instruments memory accesses at compile time to catch buffer overflows, use-after-free, and other memory bugs with roughly 2x slowdown (much faster than Valgrind).
ASan adds redzones (poisoned memory) around every allocation and maintains a shadow memory map:
Compile with:
cLoading…
ASan detects stack-buffer-overflow, heap-buffer-overflow, use-after-free, and global-buffer-overflow with detailed stack traces showing the exact source line.
You will compute the shadow-memory layout for a heap allocation and grade a memory access against it, byte exactly like ASan does: full 8-byte granules shadow as 00, the tail granule of a non-multiple-of-8 allocation shadows as the number of accessible bytes (01-07), and the heap right redzone shadows as 0xfb. Given an access offset, you decide whether it is addressable or poisoned: the exact arithmetic behind every heap-buffer-overflow report.
Combine -fsanitize=address with -g for source-line stack traces. Set ASAN_OPTIONS=detect_leaks=1 to catch memory leaks alongside overflow detection. ASan adds roughly 2x runtime overhead, making it practical for test suites but not production deployment. Pair ASan with fuzzing (libFuzzer, AFL) to find bugs that only trigger on specific inputs. MSan covers uninitialized reads that ASan misses.
Write a C program that computes an ASan shadow-memory layout and grades an access against it.
Requirements:
Success Criteria: