Update section Exploit Strategy

This commit is contained in:
Damian Pfammatter
2024-04-30 15:13:04 +02:00
parent 0016238b0c
commit 14002c42bc
2 changed files with 24 additions and 10 deletions
+23 -9
View File
@@ -181,7 +181,7 @@ controlled argument (command string). The corresponding chain is depicted in Fig
<figure>
<img src="../images/ROP_Chain.svg" alt="ROP Chain"/>
<figcaption>
Figure 6.1: ROP Chain - Simple ROP chain, calling the function system@libc with a controlled
Figure 6.1: ROP Chain - ROP chain calling the libc function system with a controlled
argument.
</figcaption>
</figure>
@@ -191,21 +191,36 @@ Gadget 0 corresponds to the `pop` instruction at address `0xcf24` that we invest
section
[Exploitation: Vulnerability Characteristics](./6_exploitation.md#vulnerability-characteristics). We
have already seen that, due to the `pop` instruction, the *pc* receives a value we control. We will
try making the *pc* become the value `0xc9b8`, which corresponds to the address of gadget 1. As gadget 1, we choose one that consists of the following two instructions:
try making the *pc* become the value `0xc9b8`, so that control gets transferred to gadget 1. As
gadget 1, we choose one that consists of the following two instructions:
- `mov r0, r6`: Move the value of register *r6* (that is based on a symbolic variable) to register
*r0*.
- `bl #0x94a0 <system@plt>`: Call function `system` from *libc*, using register *r0* as argument
(synopsis: `int system(const char *command)`).
**Note**: Several (open-source) tools exist that help finding suitable ROP gadgets in
your targets. One such tool for instance is [ropper](https://github.com/sashs/Ropper).
- Mention that it will crash the binary, the binary however restarts after a crash, so no big deal
- The mentioned chain works and is easy to explain Morion's features
On the one hand, this ROP chain is simple to understand, suitable to demonstrate some features of [Morion](https://github.com/pdamian/morion), and yet powerful enough to start a reverse shell
on the targeted devices (as we will see in a moment). On the other hand, though, it will crash the
binary after function `system` returns. For the sake of demonstration, this is not a problem, since
the binary `circled` restarts after a crash. However, in the more general sense, a crashing binary
might lead to alerts, which threat actors typically want to avoid.
**Note**: Several (open-source) tools (e.g. [ropper](https://github.com/sashs/Ropper)) exist that
help finding suitable ROP gadgets in your targets.
#### Position-Independent Executable (PIE)
- Due to no PIE, gadget 1 is at a fixed known address (`0xc9b8`)
As can be seen in the output of [checksec](https://github.com/slimm609/checksec.sh) above, the
binary `circled` is not a **Position-Independent Executable (PIE)**. Its code is therefore always
loaded at virtual memory address `0x8000`. With respect to our ROP chain this means that gadget 1
can always be found at address `0xc9b8`.
#### Address Space Layout Randomization (ASLR)
Another relevant protection measure to discuss, is **Address Space Layout Randomization (ASLR)**. As
opposed to properties NX and PIE, which belong to the binary `circled` itself, ASLR is a system,
respectively kernel feature. The NETGEAR R6700v3 routers that we target, make use of **partial** (or
conservative) **ASRL** (as we also configured it in our [setup](./1_setup.md#armhf-guest-system)).
This means that components such as shared libraries, stack, heap, mmap and VDSO are randomized, i.e.
loaded at different addresses at each run.
With respect to our intended ROP chain (as depicted in Figure 6.1), this means that we cannot use a
fix stack address for our command string.
- defeat ASLR
- binary restarts after a crash
@@ -213,7 +228,6 @@ your targets. One such tool for instance is [ropper](https://github.com/sashs/Ro
1 - Conservative Randomization: Shared libraries, **stack**, mmap(), VDSO and heap are randomized
- As the process restarts after crashing, we have almost unlimited tries to find the correct address
- (Characters we might not use: null-bytes, space, carriage return)
### Payload Generation
[circled.rop1.py](../morion/circled.rop1.py#L10):
```python
+1 -1
View File
File diff suppressed because one or more lines are too long

Before

Width:  |  Height:  |  Size: 216 KiB

After

Width:  |  Height:  |  Size: 26 KiB