Format String Vulnerabilities Course

This course introduces format string vulnerabilities, their exploitation and possible mitigations.

32 minutes

Course description

Print statements are a deceptively simple aspect of programming. By exploiting format string vulnerabilities, an attacker can read from or write to arbitrary memory within a program. This course describes how to identify format string vulnerabilities and how to write code that is not vulnerable to attack.


Format String Demo

Video - 00:06:00

This video demonstrates exploitation of a format string vulnerability.
Format String Mitigations

Video - 00:03:00

This video describes mitigations for format string vulnerabilities.
Format String Vulnerability Case Study

Video - 00:05:00

This video describes a case study of an application containing a format string vulnerability.
Exploiting Format String Vulnerabilities

Video - 00:06:00

This video describes how format string vulnerabilities can be exploited by an attacker.
Format String Vulnerabilities

Video - 00:05:00

This video describes how format string vulnerabilities can make an application vulnerable to attack.
Introduction to Printing

Video - 00:07:00

This video covers the fundamentals of printing and format strings.
Introduction to Format String Vulnerabilities

Video - 00:02:00

This video provides an introduction to the format string vulnerabilities course.

Meet the author

Howard Poston

Howard Poston is a copywriter, author, and course developer with experience in cybersecurity and blockchain security, cryptography, and malware analysis. He has an MS in Cyber Operations, a decade of experience in cybersecurity, and over five years of experience as a freelance consultant providing training and content creation for cyber and blockchain security. He is also the creator of over a dozen cybersecurity courses, has authored two books, and has spoken at numerous cybersecurity conferences. He can be reached by email at or via his website at

Unlock 7 days of free training

  • 1,400+ hands-on courses and labs
  • Certification practice exams
  • Skill assessments

Associated NICE Work Roles

All Infosec training maps directly to the NICE Workforce Framework for Cybersecurity to guide you from beginner to expert across 52 Work Roles.

  • Cyber Operator
  • Law Enforcement / Counterintelligence Forensics Analyst
  • Cyber Defense Forensics Analyst

Plans & pricing

Infosec Skills Personal

$299 / year

  • 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Custom certification practice exams (e.g., CISSP, Security+)
  • Skill assessments
  • Infosec peer community support

Infosec Skills Teams

$799 per license / year

  • Team administration and reporting
  • Dedicated client success manager
  • Single sign-on (SSO)
    Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
  • Integrations via API
    Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
  • 190+ role-guided learning paths and assessments (e.g., Incident Response)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Create and assign custom learning paths
  • Custom certification practice exams (e.g., CISSP, CISA)
  • Optional upgrade: Guarantee team certification with live boot camps

Learn about scholarships and financing with

Affirm logo

Award-winning training you can trust