> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/notes-mcs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/notes-mcs/analysis-and-exploration-of-vulnerabilities/buffers/why-memory-structure-101.md).

# Why? Memory Structure 101

Kernel organizes memory in pages.

* Typically 4096 bytes.

Processes operate in a Virtual Memory Space.

* Mapped to real pages, which can be in RAM or Swapped.

Kernel splits program in several segments.

* Increases security.
  * segment based permissions.
* Increases performance.
  * some are dynamic: invalidated when program terminates.
  * some are static: can be retained, speed repeated startup.

## Memory Structure

<figure><img src="https://3744219775-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUaTnynVhA2CYjsGJT14j%2Fuploads%2Fw0qcwEkkgUU07WA0Woje%2F2023-11-25_14-43.png?alt=media&amp;token=bd3258b9-8de4-4e67-9fca-954c4dffb50f" alt=""><figcaption></figcaption></figure>

* **SS**: Local variables and execution flow
* **Shared Libraries**: .so/dlls loaded.
  * Addresses are shared between programs.
* **Heap**: memory allocated with malloc/new.
* **BSS**: Global Variables.
* **Data**: Constants.
* **Code**: Actual instructions.

## mem.c

Simple program showing the memory map of itself.

Features:

* Prints the address of objects of different types.
  * Argument.
  * Dynamic memory with malloc.
  * Global Variable.
  * Constant.
  * Function
* Prints the memory maps as exposed in /proc/self/maps.
* Creates a recursive function and prints the address of local variables.
* Crashes with a Stack Overflow.

<figure><img src="https://3744219775-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUaTnynVhA2CYjsGJT14j%2Fuploads%2FoJAUq6wuinkjaUTiCgh9%2F2023-11-25_14-49.png?alt=media&amp;token=e266c71c-6994-4f24-a18a-bfb6af860987" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3744219775-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUaTnynVhA2CYjsGJT14j%2Fuploads%2FVbdbjtAtlyhcmt4sL9K3%2F2023-11-25_14-58.png?alt=media&amp;token=13fa644b-7e04-42f1-aa4a-f8b95051a0a2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3744219775-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUaTnynVhA2CYjsGJT14j%2Fuploads%2F2gg8FmE0NShGKMvYlpsg%2F2023-11-25_15-01.png?alt=media&amp;token=b0255789-d545-4f95-a171-30b09aad78dd" alt=""><figcaption></figcaption></figure>

## Stack organization

Stack is organized by frames, one for each function call.

* Memory reserved for the function to use as it requires.

Each stack frame stores:

* Return Information.
* Local Variables.
* Arguments to following functions (x32: all, x64: +5th).

Return information has 2 major objectives.

* Chaining frames as new functions are called.
* Return to the next instruction after the function ends.

Frame chaining.

* When a function is called, the address of the current stack frame (Register RBP in x64) is push to the frame.
* When the function ends, RBP is popped.
  * Caller function has it’s frame restored.

Function chaining

* When a function is called, the address of the next instruction is push to the stack (RIP register).
* When a function ends, that address is popped.
  * Execution resumes at the caller function.

## mem\_local.c

Prints the address to several variables.

* Local variables declared in the main function.
* Arguments passed to the foo function.
* Local variables in the foo function.

```
main
argc : 0x7fffd6baeddc
argv : 0x7fffd6baeed8

foo
a       : 0x7fffd6baed8c
local_a : 0x7fffd6baed9b
buffer  : 0x7fffd6baeda0
local_b : 0x7fffd6baed9c
```

```c
char foo(int a,){
    char local_a = 3;
    char buffer[16];
    int local_b = 5;

    printf(“%p\n”,&a);
    printf(“%p\n”,&local_a);
    printf(“%p\n”,&buffer);
    printf(“%p\n”,&local_b);
    
    buffer[0] = local_a;
    return buffer[0];
}

int main(int argc, char* argv[]){
    printf(“%p\n”, &argc);
    printf(“%p\n”, argv);
 
    return foo(argc);
}
```

Stack frame grows from higher addresses to lower addresses.

* Main has variables at 0xbaedb.
* Foo has variables at 0xbaed6-8.

Declaration order doesn’t matter!

Compiler will place variables are he seems adequate.

* Will keep information aligned.
* May create empty spaces.
* May deploy additional protection mechanisms (canaries).

## mem.c

<figure><img src="https://3744219775-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUaTnynVhA2CYjsGJT14j%2Fuploads%2FmkHw7KWvSuwII057d41V%2F2023-11-25_15-08.png?alt=media&amp;token=d05e9a90-ffe7-49d5-84e9-20959cc1b3a4" alt=""><figcaption></figcaption></figure>

1. Until evolution: a limit imposed by the SO is reached.
2. Until vital memory is overwritten.

<figure><img src="https://3744219775-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUaTnynVhA2CYjsGJT14j%2Fuploads%2FJSThf9eMMLAlw1WAGwLJ%2F2023-11-25_15-09.png?alt=media&amp;token=e48b4735-f879-4079-922d-a7396ae76ca0" alt=""><figcaption></figcaption></figure>
