Update Analysis section

This commit is contained in:
Damian Pfammatter
2024-04-24 09:05:37 +02:00
parent d04419250d
commit 35ff327ab6
+8 -8
View File
@@ -39,8 +39,8 @@ could trick vulnerable routers to download a malicious file (e.g. using DNS or T
leading to arbitrary code being executed on the router. Since `circled` runs as *root*, attackers
may gain full privileges on the targeted devices.
## Analysis
In the following, we examine some excerpts from the **reverse engineered binary** and discuss its
improper handling of buffer sizes that culminates in the stack buffer overflow we intend to exploit.
In the following, we examine some excerpts of the **reverse engineered binary** and discuss its
improper handling of buffer sizes that culminate in the stack buffer overflow we intend to exploit.
Figure 1 shows the de-compiled pseudo C-code that deals with the **reading and parsing** of file
`/tmp/circleinfo.txt` - a copy of the downloaded file as mentioned in the previous section. Using
@@ -48,8 +48,8 @@ the *libc* function `fgets`, the file's content is read line-by-line into a stac
called `line`) of size 1024 (0x400). Using the *libc* function `sscanf`, each read line is then
split into two strings (space-separated), which are copied to stack buffers `db_checksum` and
`db_checksum_val`, respectively. As long as the string in buffer `db_checksum` is not equal to
`"db_checksum"` (*libc* function `strcmp`), we move on to the next line in the file, if there is any
left. The buffer `line` may therefore contain a maximum of 1023 characters (plus a terminating
`"db_checksum"` (see *libc* function `strcmp`), we move on to the next line in the file, if there is
any left. The buffer `line` may therefore contain a maximum of 1023 characters (plus a terminating
null-byte).
<hr>
<figure>
@@ -61,8 +61,9 @@ null-byte).
<hr>
As can be seen in Figure 2 below, stack buffers `db_checksum` and `db_checksum_val`, however, only
have a size of 256 bytes each. A line e.g. consisting of the string `"A"*1021 + " X"` will therefore
lead to a **stack buffer overflow** (of buffer `db_checksum` in the listed example string).
have a size of 256 bytes each. A line, e.g. consisting of the string `"A"*1021 + " X"`, will
therefore lead to a **stack buffer overflow** (of buffer `db_checksum` in the listed example) since
the first copied string will have a length of 1021.
<hr>
<figure>
<img src="../images/RE_Vuln_01.svg" alt="Initializing of stack buffers"/>
@@ -100,8 +101,7 @@ so easy to determine, and typically requires time-consuming reverse engineering
efforts. As we will see in the next chapter about [Exploitation](./6_exploitation.md), this is where
[Morion](https://github.com/pdamian/morion), respectively **symbolic execution**, might help us by
simplifying certain tasks, so that we do not have to understand all subtleties in full detail (e.g.
which bytes we control, are byte values restricted - bad characters, etc.) to craft a working
exploit.
which bytes we control, are byte values restricted, etc.) to craft a working exploit.
## Memory Layout PoV
PoV Payload: `b'A'*1021 + b' X'`