From 14002c42bc86698ecaed29b0612e70b9f8c8ff1f Mon Sep 17 00:00:00 2001 From: Damian Pfammatter Date: Tue, 30 Apr 2024 15:13:04 +0200 Subject: [PATCH] Update section Exploit Strategy --- docs/6_exploitation.md | 32 +++++++++++++++++++++++--------- images/ROP_Chain.svg | 2 +- 2 files changed, 24 insertions(+), 10 deletions(-) diff --git a/docs/6_exploitation.md b/docs/6_exploitation.md index e418ffc..c671b9e 100644 --- a/docs/6_exploitation.md +++ b/docs/6_exploitation.md @@ -181,7 +181,7 @@ controlled argument (command string). The corresponding chain is depicted in Fig
ROP Chain
- Figure 6.1: ROP Chain - Simple ROP chain, calling the function system@libc with a controlled + Figure 6.1: ROP Chain - ROP chain calling the libc function system with a controlled argument.
@@ -191,21 +191,36 @@ Gadget 0 corresponds to the `pop` instruction at address `0xcf24` that we invest section [Exploitation: Vulnerability Characteristics](./6_exploitation.md#vulnerability-characteristics). We have already seen that, due to the `pop` instruction, the *pc* receives a value we control. We will -try making the *pc* become the value `0xc9b8`, which corresponds to the address of gadget 1. As gadget 1, we choose one that consists of the following two instructions: +try making the *pc* become the value `0xc9b8`, so that control gets transferred to gadget 1. As +gadget 1, we choose one that consists of the following two instructions: - `mov r0, r6`: Move the value of register *r6* (that is based on a symbolic variable) to register *r0*. - `bl #0x94a0 `: Call function `system` from *libc*, using register *r0* as argument (synopsis: `int system(const char *command)`). -**Note**: Several (open-source) tools exist that help finding suitable ROP gadgets in -your targets. One such tool for instance is [ropper](https://github.com/sashs/Ropper). - -- Mention that it will crash the binary, the binary however restarts after a crash, so no big deal -- The mentioned chain works and is easy to explain Morion's features +On the one hand, this ROP chain is simple to understand, suitable to demonstrate some features of [Morion](https://github.com/pdamian/morion), and yet powerful enough to start a reverse shell +on the targeted devices (as we will see in a moment). On the other hand, though, it will crash the +binary after function `system` returns. For the sake of demonstration, this is not a problem, since +the binary `circled` restarts after a crash. However, in the more general sense, a crashing binary +might lead to alerts, which threat actors typically want to avoid. +**Note**: Several (open-source) tools (e.g. [ropper](https://github.com/sashs/Ropper)) exist that +help finding suitable ROP gadgets in your targets. #### Position-Independent Executable (PIE) -- Due to no PIE, gadget 1 is at a fixed known address (`0xc9b8`) +As can be seen in the output of [checksec](https://github.com/slimm609/checksec.sh) above, the +binary `circled` is not a **Position-Independent Executable (PIE)**. Its code is therefore always +loaded at virtual memory address `0x8000`. With respect to our ROP chain this means that gadget 1 +can always be found at address `0xc9b8`. #### Address Space Layout Randomization (ASLR) +Another relevant protection measure to discuss, is **Address Space Layout Randomization (ASLR)**. As +opposed to properties NX and PIE, which belong to the binary `circled` itself, ASLR is a system, +respectively kernel feature. The NETGEAR R6700v3 routers that we target, make use of **partial** (or +conservative) **ASRL** (as we also configured it in our [setup](./1_setup.md#armhf-guest-system)). +This means that components such as shared libraries, stack, heap, mmap and VDSO are randomized, i.e. +loaded at different addresses at each run. + +With respect to our intended ROP chain (as depicted in Figure 6.1), this means that we cannot use a +fix stack address for our command string. - defeat ASLR - binary restarts after a crash @@ -213,7 +228,6 @@ your targets. One such tool for instance is [ropper](https://github.com/sashs/Ro 1 - Conservative Randomization: Shared libraries, **stack**, mmap(), VDSO and heap are randomized - As the process restarts after crashing, we have almost unlimited tries to find the correct address - (Characters we might not use: null-bytes, space, carriage return) - ### Payload Generation [circled.rop1.py](../morion/circled.rop1.py#L10): ```python diff --git a/images/ROP_Chain.svg b/images/ROP_Chain.svg index 833a6d5..ce5d313 100644 --- a/images/ROP_Chain.svg +++ b/images/ROP_Chain.svg @@ -1,4 +1,4 @@ -
Gadget 0
Gadget 1
0x0000cf24
0x0000c9b8
0x0000c9bc
ADDRESS
PRECONDITIONS (#Gadget.#Instruction)
pc == [sp+8*4] == 0xc9b8
pop {r4, r5, r6, r7, r8, r9, r10,r11, pc}
mov r0, r6
bl #0x94a0 <system@plt>
INSTRUCTION
PRECON 0.0
r6 == cmd == 0xbeffc0c4+396 == 0xbeffc250
cmd[0] == 0x69 'i'
cmd[1] == 0x64 'd'
...
PRECON 1.1
PRECON 1.0
\ No newline at end of file +
Gadget 0
Gadg...
Gadget 1
Gadg...
0x0000cf24
0x0000cf24
0x0000c9b8
0x0000c9b8
0x0000c9bc
0x0000c9bc
ADDRESS
ADDRESS
PRECONDITIONS (#Gadget.#Instruction)
PRECONDITIONS (#Gadget.#Instruction)
pc == [sp+8*4] == 0xc9b8
pc == [sp+8*4] == 0xc9b8
pop {r4, r5, r6, r7, r8, r9, r10,r11, pc}
pop {r4, r5, r6, r7, r8, r9, r10,r11, pc}
mov r0, r6
mov r0, r6
bl #0x94a0 <system@plt>
bl #0x94a0 <system@plt>
INSTRUCTION
INSTRUCTION
PRECON 0.0
PRECON 0.0
r0 == cmd == 0xbeffc0c4+396 == 0xbeffc250
cmd[0] == 0x69 'i'
cmd[1] == 0x64 'd'
...
r0 == cmd == 0xbeffc0c4+396 == 0xbeffc250...
PRECON 1.1
PRECON 1.1
PRECON 1.0
PRECON 1.0
Text is not SVG - cannot display
\ No newline at end of file