This C function has a critical bug. Can you spot it?
void login(char *input) {
char buf[64];
strcpy(buf, input); // ← no bounds check!
}strcpy copies data without checking length — what happens if input > 64 bytes?
// Simulated environment. Real attacks work exactly like this.