{"id":369,"date":"2010-07-03T10:05:41","date_gmt":"2010-07-03T18:05:41","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=369"},"modified":"2010-07-03T10:05:41","modified_gmt":"2010-07-03T18:05:41","slug":"gdb-turns-off-aslr","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2010\/07\/03\/gdb-turns-off-aslr\/","title":{"rendered":"gdb turns off ASLR"},"content":{"rendered":"<p>Starting with GDB version 7, first appearing in Ubuntu with Karmic (Ubuntu 9.10), ASLR is <a href=\"http:\/\/sourceware.org\/gdb\/current\/onlinedocs\/gdb\/Starting.html#index-set-disable_002drandomization-109\">turned off<\/a> (via the ADDR_NO_RANDOMIZE personality flag) for the debugged process.  If you want a more realistic view of how a process will appear in memory, you must &#8220;<code>set disable-randomization off<\/code>&#8221; in gdb:<\/p>\n<pre class=\"brush:shell\">\r\n$ gdb \/usr\/bin\/something\r\n...\r\n(gdb) show disable-randomization\r\nDisabling randomization of debuggee's virtual address space is on.\r\n(gdb) start\r\n...\r\n(gdb) ^Z\r\n$ cat \/proc\/$(pidof \/usr\/bin\/something)\/personality\r\n00040000\r\n$ grep 0040000 \/usr\/include\/linux\/personality.h\r\n    ADDR_NO_RANDOMIZE =     0x0040000,  \/* disable randomization of VA space *\/\r\n$ fg\r\n(gdb) set disable-randomization off\r\n(gdb) show disable-randomization\r\nDisabling randomization of debuggee's virtual address space is off.\r\n(gdb) start\r\n...\r\n(gdb) ^Z\r\n$ cat \/proc\/$(pidof \/usr\/bin\/something)\/personality\r\n00000000\r\n<\/pre>\n<p style='text-align:left'>&copy; 2010, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Starting with GDB version 7, first appearing in Ubuntu with Karmic (Ubuntu 9.10), ASLR is turned off (via the ADDR_NO_RANDOMIZE personality flag) for the debugged process. If you want a more realistic view of how a process will appear in memory, you must &#8220;set disable-randomization off&#8221; in gdb: $ gdb \/usr\/bin\/something &#8230; (gdb) show disable-randomization [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,18,14,19],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/369"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=369"}],"version-history":[{"count":1,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/369\/revisions"}],"predecessor-version":[{"id":370,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/369\/revisions\/370"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}