mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
Update section Exploit Strategy
This commit is contained in:
+23
-9
@@ -181,7 +181,7 @@ controlled argument (command string). The corresponding chain is depicted in Fig
|
||||
<figure>
|
||||
<img src="../images/ROP_Chain.svg" alt="ROP Chain"/>
|
||||
<figcaption>
|
||||
Figure 6.1: ROP Chain - Simple ROP chain, calling the function system@libc with a controlled
|
||||
Figure 6.1: ROP Chain - ROP chain calling the libc function system with a controlled
|
||||
argument.
|
||||
</figcaption>
|
||||
</figure>
|
||||
@@ -191,21 +191,36 @@ Gadget 0 corresponds to the `pop` instruction at address `0xcf24` that we invest
|
||||
section
|
||||
[Exploitation: Vulnerability Characteristics](./6_exploitation.md#vulnerability-characteristics). We
|
||||
have already seen that, due to the `pop` instruction, the *pc* receives a value we control. We will
|
||||
try making the *pc* become the value `0xc9b8`, which corresponds to the address of gadget 1. As gadget 1, we choose one that consists of the following two instructions:
|
||||
try making the *pc* become the value `0xc9b8`, so that control gets transferred to gadget 1. As
|
||||
gadget 1, we choose one that consists of the following two instructions:
|
||||
- `mov r0, r6`: Move the value of register *r6* (that is based on a symbolic variable) to register
|
||||
*r0*.
|
||||
- `bl #0x94a0 <system@plt>`: Call function `system` from *libc*, using register *r0* as argument
|
||||
(synopsis: `int system(const char *command)`).
|
||||
|
||||
**Note**: Several (open-source) tools exist that help finding suitable ROP gadgets in
|
||||
your targets. One such tool for instance is [ropper](https://github.com/sashs/Ropper).
|
||||
|
||||
- Mention that it will crash the binary, the binary however restarts after a crash, so no big deal
|
||||
- The mentioned chain works and is easy to explain Morion's features
|
||||
On the one hand, this ROP chain is simple to understand, suitable to demonstrate some features of [Morion](https://github.com/pdamian/morion), and yet powerful enough to start a reverse shell
|
||||
on the targeted devices (as we will see in a moment). On the other hand, though, it will crash the
|
||||
binary after function `system` returns. For the sake of demonstration, this is not a problem, since
|
||||
the binary `circled` restarts after a crash. However, in the more general sense, a crashing binary
|
||||
might lead to alerts, which threat actors typically want to avoid.
|
||||
|
||||
**Note**: Several (open-source) tools (e.g. [ropper](https://github.com/sashs/Ropper)) exist that
|
||||
help finding suitable ROP gadgets in your targets.
|
||||
#### Position-Independent Executable (PIE)
|
||||
- Due to no PIE, gadget 1 is at a fixed known address (`0xc9b8`)
|
||||
As can be seen in the output of [checksec](https://github.com/slimm609/checksec.sh) above, the
|
||||
binary `circled` is not a **Position-Independent Executable (PIE)**. Its code is therefore always
|
||||
loaded at virtual memory address `0x8000`. With respect to our ROP chain this means that gadget 1
|
||||
can always be found at address `0xc9b8`.
|
||||
#### Address Space Layout Randomization (ASLR)
|
||||
Another relevant protection measure to discuss, is **Address Space Layout Randomization (ASLR)**. As
|
||||
opposed to properties NX and PIE, which belong to the binary `circled` itself, ASLR is a system,
|
||||
respectively kernel feature. The NETGEAR R6700v3 routers that we target, make use of **partial** (or
|
||||
conservative) **ASRL** (as we also configured it in our [setup](./1_setup.md#armhf-guest-system)).
|
||||
This means that components such as shared libraries, stack, heap, mmap and VDSO are randomized, i.e.
|
||||
loaded at different addresses at each run.
|
||||
|
||||
With respect to our intended ROP chain (as depicted in Figure 6.1), this means that we cannot use a
|
||||
fix stack address for our command string.
|
||||
|
||||
- defeat ASLR
|
||||
- binary restarts after a crash
|
||||
@@ -213,7 +228,6 @@ your targets. One such tool for instance is [ropper](https://github.com/sashs/Ro
|
||||
1 - Conservative Randomization: Shared libraries, **stack**, mmap(), VDSO and heap are randomized
|
||||
- As the process restarts after crashing, we have almost unlimited tries to find the correct address
|
||||
- (Characters we might not use: null-bytes, space, carriage return)
|
||||
|
||||
### Payload Generation
|
||||
[circled.rop1.py](../morion/circled.rop1.py#L10):
|
||||
```python
|
||||
|
||||
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 216 KiB After Width: | Height: | Size: 26 KiB |
Reference in New Issue
Block a user