Students bypass school's code grader by calling execve without naming it

Calling a function in C without naming it

A school's automated grading system uses clang to parse code and block forbidden functions like execve. Two students found a way around it: they leak the fixed offset between printf and mmap, then use mmap to get a writable and executable page, copy in a tiny syscall stub, and invoke execve by its syscall number. The exploit works despite ASLR and ASan, and they reported it to the school.

Because we know our code is compiled with ASan, we chose to leak the offset between printf, a function that is always allowed, and mmap, a function that gives us arbitrary assembly code execution.
  1. ashdnazg

    Our university was far less careful, and just ran our submissions in the same network as everything else albeit on a user with barely any permissions.

    Once when the automatic tests crashed my submission, I simply used `system` to dump the testing input into my home dir. I forgot, however, to setup the permissions, so I couldn't really access it! A couple more resubmissions with extra chmods, messing up a different thing every time and I managed to reproduce my bug, fix it, resubmit and purge all (or most) evidence.

  2. Kevin_Flynn

    Because we know our code is compiled with ASan, we chose to leak the offset between printf, a function that is always allowed, and mmap, a function that gives us arbitrary assembly code execution. We can thus bypass the school's checks and call any syscall, in our case execve to get shell access.

    We did not investigate further and simply reported this possible issue to the school.

    I see no trivial way of patching this.

    The flaw seems to be in the submission system.

    The submission system could build/relink your code to a trampoline library with the body of each function to be banned replaced with error reporting and abort. In your example, it would trap:

    char *code =

    notmmap.fn(NULL, 4096, PROT_READ | PROT_WRITE | PROT_EXEC,

    MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);

    and prevent you from using the PROT_EXEC flag during the execution phase of submission validation.

    According to AI, on linux: "... a seccomp-BPF filter applied to each process before it starts running the program. It can inspect the prot argument to mmap and return EPERM when PROT_EXEC is set."

    Additionally, on linux: "systemd offers MemoryDenyWriteExecute=yes for services. That is less restrictive than banning every executable mapping: it targets writable+executable mappings and related ways of making memory executable. "

    ( IF ... i read the article correctly )

    ps. Submit the proposed solutions to your department head or other authority figure who may throw you some sort of bone such that your sta […]

  3. PeterWhittaker

    Sounds like the school needs to wrap things in a seccomp denylist. Potentially non-trivial, but potentially interesting.

More from this day

2026-10-08