スキル一覧に戻る
waiwai24

detecting-buffer-overflows

by waiwai24

1🍴 0📅 2026年1月4日
GitHubで見るManusで実行

SKILL.md


name: detecting-buffer-overflows description: Detects stack and heap buffer overflow vulnerabilities in binary code by identifying unsafe memory operations. Use when analyzing buffer handling, string manipulation functions, or investigating memory corruption vulnerabilities.

Buffer Overflow Detection

Detection Workflow

  1. Identify dangerous function calls: strcpy, strcat, sprintf, gets, memcpy without size checks
  2. Trace data flow: Use xrefs_to from input sources (network, files, user input) to sinks
  3. Verify bounds checking: For each copy operation, check if source size is validated and destination buffer is sufficient
  4. Assess exploitability: Can attacker control overflow size? Is there controlled write to critical memory?

Key Patterns

  • Stack overflow: Unbounded copy to local buffer
  • Heap overflow: Malloc followed by unchecked write
  • Off-by-one: Loop condition or bounds check error
  • Integer overflow leading to buffer overflow

Output Format

Report with: id, type (stack/heap/static), severity, confidence, location, sink, source, buffer size, overflow potential, evidence, exploitability, mitigation.

Severity Guidelines

  • CRITICAL: Unbounded copy to stack buffer, attacker-controlled size
  • HIGH: Bounded copy with insufficient checks, off-by-one errors
  • MEDIUM: Potential overflow with limited attacker control
  • LOW: Unlikely to be exploitable, theoretical only

See Also

  • patterns.md - Detailed detection patterns and exploitation scenarios
  • examples.md - Example analysis cases and code samples
  • references.md - CWE references and mitigation strategies

スコア

総合スコア

55/100

リポジトリの品質指標に基づく評価

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

+10
説明文

100文字以上の説明がある

0/10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新がある

0/10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

0/5
タグ

1つ以上のタグが設定されている

0/5

レビュー

💬

レビュー機能は近日公開予定です