Back to Skills

format-string-exploitation

Format string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary stack reads (%p/%s), arbitrary memory writes (%n/%hn/%hhn), GOT/hook overwrites, and canary/libc/PIE leaks.

1,281stars175forksUpdated 7/5/2026

Security Assessment

Safe(100/100)
Security Score100/100

About format-string-exploitation

An expert attack playbook for exploiting format string vulnerabilities, the class of bugs that arises when printf-family functions such as printf, fprintf, sprintf, and snprintf receive a user-controlled format argument. When an attacker controls the format string, format specifiers become primitives: %p and %s turn into arbitrary stack and memory reads, while %n, %hn, and %hhn become arbitrary memory writes. The playbook walks through confirming the vulnerability (for example sending AAAA%p%p%p... and watching for 0x4141414141414141 to locate the input offset) and distinguishing vulnerable calls from safe fixed-format usage.

The reading section covers sequential and positional stack leaks (%p versus %N$p), dereferencing pointers with %s, and leaking specific targets such as stack canaries, saved RBP, return addresses for PIE base calculation, and libc addresses. The writing section details byte-, short-, and int-width writes with separate 32-bit and 64-bit strategies, notably placing addresses after the format specifiers on 64-bit so embedded null bytes do not terminate the string. Automation is handled through pwntools, using fmtstr_payload() for one-shot GOT overwrites and the interactive FmtStr class with auto-detected offsets.

Later sections turn a write primitive into code execution: overwriting GOT entries (printf, strlen, puts, atoi, exit) to redirect to system, and hook targets like __malloc_hook and __free_hook on glibc before 2.34. Advanced material covers stack pointer chain exploitation when the format string is not directly on the stack, two-stage writes through existing pointer chains, and a blind methodology for remote services with no binary or source. Use it during CTF challenges or real-world binary exploitation whenever a printf-family sink is reachable with attacker input, or when combining a format string leak with stack overflow, canary/PIE/ASLR bypass, or heap exploitation.

FAQ

When is a printf call vulnerable to format string exploitation?

It is vulnerable when user input is passed directly as the format argument, as in printf(user_input) or sprintf(buf, user_input). Passing input as a data argument with a fixed format, such as printf("%s", user_input), is safe.

How do I find the offset where my input appears on the stack?

Send a marker like AAAAAAAA followed by a series of %p specifiers and look for 0x41414141 (or 0x4141414141414141) in the output. The doc also shows a loop sending AAAA%{i}$p and checking each position until the marker appears.

Why does the 64-bit write technique place addresses after the format specifiers?

On 64-bit, target addresses like 0x00007fXXXXXXXX contain null bytes that would terminate the format string early. Placing the addresses after the specifiers, padded to 8-byte alignment, avoids truncation.

Does the skill support automated payload generation?

Yes. It uses pwntools fmtstr_payload() with an offset, an address-to-value map, and a write_size of byte, short, or int, and also documents the interactive FmtStr class whose offset is auto-detected and which applies writes via execute_writes().

Can a format string bug lead to code execution?

Yes. The write primitive can overwrite GOT entries such as printf, strlen, puts, atoi, or exit to redirect to system, or overwrite hooks like __malloc_hook or __free_hook on glibc before 2.34.

Install format-string-exploitation

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill