From 20ad30b3fc677b119eefec589193c26cbeecb3ce Mon Sep 17 00:00:00 2001 From: Damian Pfammatter Date: Fri, 13 Dec 2024 09:49:21 +0100 Subject: [PATCH] Added references to videos --- docs/3_tracing.md | 8 -------- docs/4_symbex.md | 2 -- docs/6_exploitation.md | 14 -------------- 3 files changed, 24 deletions(-) diff --git a/docs/3_tracing.md b/docs/3_tracing.md index 9e0d357..0af645f 100644 --- a/docs/3_tracing.md +++ b/docs/3_tracing.md @@ -77,10 +77,8 @@ trace should include both the points where attacker-controllable inputs are intr these inputs lead to a potential vulnerability (e.g. the point the binary is crashing due to a memory violation condition - as for instance found by a fuzzing campaign). - ### YAML File Next, the file [circled.init.yaml](../morion/circled.init.yaml) needs to be defined. It typically @@ -171,10 +169,8 @@ is hard to determine (e.g. tail calls). And more importantly, to function calls, but be applicable in more generic cases, i.e. for any sequence of subsequent assembly instructions. - ## Run Use the following steps to create a **trace** of the binary _circled_, while it is targeted with a @@ -200,10 +196,8 @@ _proof-of-vulnerability (PoV)_ payload (as for instance being identified by a fu gdb-multiarch -q -x circled.trace.gdb # Use GDB for cross-platform remote trace collection ``` - ## Discussion In the following, we discuss some aspects of the tracing process as implemented by @@ -342,10 +336,8 @@ stack that led to an invalid program counter (`pc` register), and in consequence can help us to decide whether this situation is [exploitable](./6_exploitation.md) or not, and if so, how we can do it. - ### How Hooking Works As mentioned before, hooking allows a specified **sequence of assembly instructions** (e.g. diff --git a/docs/4_symbex.md b/docs/4_symbex.md index e8be553..a542ffe 100644 --- a/docs/4_symbex.md +++ b/docs/4_symbex.md @@ -64,10 +64,8 @@ Remember that if you followed along the instructions in chapter [Tracing](./3_tr was collected while the vulnerable binary processed a sample payload leading to a **crasher/segfault** (as might have been identified by a fuzzer). - ### Analysis Modules [Morion](https://github.com/cyber-defence-campus/morion) implements different analysis modules that diff --git a/docs/6_exploitation.md b/docs/6_exploitation.md index 13b83c1..cc832ea 100644 --- a/docs/6_exploitation.md +++ b/docs/6_exploitation.md @@ -153,10 +153,8 @@ At this point, we learned that registers *r4*-*r11*, as well as the *pc* are bas variables that an attacker might control. We verified that we can modify the *pc* to point to another value. Further we got an intuition about the memory layout relevant for our exploit. - ### Exploit Strategy With the intention to develop an exploit strategy, let us now inspect some **security properties** @@ -388,10 +386,8 @@ elif payload == "poc1": [...] ``` - ### Run PoC Exploit Use the following steps to run the binary _circled_, while it is targeted with the @@ -437,10 +433,8 @@ pwndbg> continue If the PoC exploit worked, you will find a file `/id` on the emulated router (System: [ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`. - ## Analysis Module morion_rop_generator The above process of getting a payload for the intended ROP chain is rather cumbersome, since we @@ -640,10 +634,8 @@ elif payload == "poc2": [...] ``` - ### Run PoC Exploit Use the following steps to run the binary _circled_, while it is targeted with the @@ -689,10 +681,8 @@ pwndbg> continue If the PoC exploit worked, you will find a file `/id` on the emulated router (System: [ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`. - ## Getting a Reverse Shell With the understanding we gained so far, it is a rather simple task to turn the PoC payload into a @@ -808,19 +798,15 @@ pwndbg> continue ``` If the final exploit worked, you will receive a reverse shell on the targeted device as _root_ user. - **Note**: If you want to see how **stack brute-forcing** performs, run `/circled.sh` without attaching of the _gdbserver_, i.e. without the flag `--gdb`. You will receive the reverse shell, once the correct stack address of the system command has been found. - ## Conclusion This repository intended to demonstrate (some of) the current features (and limitations) of the