> For the complete documentation index, see [llms.txt](https://hexisanoob.gitbook.io/hexisanoob/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hexisanoob.gitbook.io/hexisanoob/enum-and-initial-compromise/buffer-overflow-prep/insecure-c-functions.md).

# Insecure C functions

Some inherently insecure functions exist in various programming languages that might help an attacker conduct buffer overflow and read/write/execute to or from a memory location that originally didn't allow a user to interact.

Example: gets() in C

<figure><img src="https://62284611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MSvRnuhl_P5WCd1fZEn%2Fuploads%2F1UCxRIRSp1zZOyG5LTPR%2Fimage.png?alt=media&amp;token=472ab2df-103a-4634-a326-2faf592a5317" alt=""><figcaption></figcaption></figure>

gets() function will just keep on reading data from a user even though the buffer we're trying to take input in is of restricted size like 32 bytes.

Exploitation is in CTF challenge learnings section
