Added references to videos

This commit is contained in:
Damian Pfammatter
2024-12-13 09:49:21 +01:00
parent 0d0bc6496f
commit 20ad30b3fc
3 changed files with 0 additions and 24 deletions
-8
View File
@@ -77,10 +77,8 @@ trace should include both the points where attacker-controllable inputs are intr
these inputs lead to a potential vulnerability (e.g. the point the binary is crashing due to a
memory violation condition - as for instance found by a fuzzing campaign).
<!--
**DEMO Tracing/Setup/GDB_Commands_Script** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/6oUEp2QjeJg/maxresdefault.jpg)](https://www.youtube.com/watch?v=6oUEp2QjeJg)
-->
### YAML File
Next, the file [circled.init.yaml](../morion/circled.init.yaml) needs to be defined. It typically
@@ -171,10 +169,8 @@ is hard to determine (e.g. tail calls). And more importantly,
to function calls, but be applicable in more generic cases, i.e. for any sequence of subsequent
assembly instructions.
<!--
**DEMO Tracing/Setup/YAML_File** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/z3axU4WM-jc/maxresdefault.jpg)](https://www.youtube.com/watch?v=z3axU4WM-jc)
-->
## Run
Use the following steps to create a **trace** of the binary _circled_, while it is targeted with a
@@ -200,10 +196,8 @@ _proof-of-vulnerability (PoV)_ payload (as for instance being identified by a fu
gdb-multiarch -q -x circled.trace.gdb # Use GDB for cross-platform remote trace collection
```
<!--
**DEMO Tracing/Run** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/ripE2dtaVtM/maxresdefault.jpg)](https://www.youtube.com/watch?v=ripE2dtaVtM)
-->
## Discussion
In the following, we discuss some aspects of the tracing process as implemented by
@@ -342,10 +336,8 @@ stack that led to an invalid program counter (`pc` register), and in consequence
can help us to decide whether this situation is [exploitable](./6_exploitation.md) or not, and if
so, how we can do it.
<!--
**DEMO Tracing/Discussion/Collecting_the_Trace** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/PrjXVZ3awz0/maxresdefault.jpg)](https://www.youtube.com/watch?v=PrjXVZ3awz0)
-->
### How Hooking Works
As mentioned before, hooking allows a specified **sequence of assembly instructions** (e.g.
-2
View File
@@ -64,10 +64,8 @@ Remember that if you followed along the instructions in chapter [Tracing](./3_tr
was collected while the vulnerable binary processed a sample payload leading to a
**crasher/segfault** (as might have been identified by a fuzzer).
<!--
**DEMO Symbolic_Execution/Run** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/emHSZWiy9P8/maxresdefault.jpg)](https://www.youtube.com/watch?v=emHSZWiy9P8)
-->
### Analysis Modules
[Morion](https://github.com/cyber-defence-campus/morion) implements different analysis modules that
-14
View File
@@ -153,10 +153,8 @@ At this point, we learned that registers *r4*-*r11*, as well as the *pc* are bas
variables that an attacker might control. We verified that we can modify the *pc* to point to
another value. Further we got an intuition about the memory layout relevant for our exploit.
<!--
**DEMO Exploitation/Analysis_Module_morion_control_hijacker/Vulnerability_Characteristics** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/SAl9rXIC4Bw/maxresdefault.jpg)](https://www.youtube.com/watch?v=SAl9rXIC4Bw)
-->
### Exploit Strategy
With the intention to develop an exploit strategy, let us now inspect some **security properties**
@@ -388,10 +386,8 @@ elif payload == "poc1":
[...]
```
<!--
**DEMO Exploitation/Analysis_Module_morion_control_hijacker/Payload_Generation** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/C_nfKRwinug/maxresdefault.jpg)](https://www.youtube.com/watch?v=C_nfKRwinug)
-->
### Run PoC Exploit
Use the following steps to run the binary _circled_, while it is targeted with the
@@ -437,10 +433,8 @@ pwndbg> continue
If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
<!--
**DEMO Exploitation/Analysis_Module_morion_control_hijacker/Run_PoC_Exploit** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/8Y7AykO99ew/maxresdefault.jpg)](https://www.youtube.com/watch?v=8Y7AykO99ew)
-->
## Analysis Module morion_rop_generator
The above process of getting a payload for the intended ROP chain is rather cumbersome, since we
@@ -640,10 +634,8 @@ elif payload == "poc2":
[...]
```
<!--
**DEMO Exploitation/Analysis_Module_morion_rop_generator/Payload_Generation** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/OAJiRpUROm4/maxresdefault.jpg)](https://www.youtube.com/watch?v=OAJiRpUROm4)
-->
### Run PoC Exploit
Use the following steps to run the binary _circled_, while it is targeted with the
@@ -689,10 +681,8 @@ pwndbg> continue
If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
<!--
**DEMO Exploitation/Analysis_Module_morion_rop_generator/Run_PoC_Exploit** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/UJskEALKLhc/maxresdefault.jpg)](https://www.youtube.com/watch?v=UJskEALKLhc)
-->
## Getting a Reverse Shell
With the understanding we gained so far, it is a rather simple task to turn the PoC payload into a
@@ -808,19 +798,15 @@ pwndbg> continue
```
If the final exploit worked, you will receive a reverse shell on the targeted device as _root_ user.
<!--
**DEMO Exploitation/Getting_a_Reverse_Shell/Run_Final_Exploit/without_ASLR** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/2q377wXwIHw/maxresdefault.jpg)](https://www.youtube.com/watch?v=2q377wXwIHw)
-->
**Note**: If you want to see how **stack brute-forcing** performs, run `/circled.sh` without
attaching of the _gdbserver_, i.e. without the flag `--gdb`. You will receive the reverse shell,
once the correct stack address of the system command has been found.
<!--
**DEMO Exploitation/Getting_a_Reverse_Shell/Run_Final_Exploit/with_ASLR** - Click the image below to watch on YouTube:
[![Demo Video](https://img.youtube.com/vi/e1GS2LsAYlQ/maxresdefault.jpg)](https://www.youtube.com/watch?v=e1GS2LsAYlQ)
-->
## Conclusion
This repository intended to demonstrate (some of) the current features (and limitations) of the