Update Analysis section

This commit is contained in:
Damian Pfammatter
2024-04-24 08:13:41 +02:00
parent 7169b4493b
commit 72bc565628
+9 -9
View File
@@ -39,29 +39,29 @@ could trick vulnerable routers to download a malicious file (e.g. using DNS or T
leading to arbitrary code being executed on the router. Since `circled` runs as *root*, attackers
may gain full privileges on the targeted devices.
## Analysis
In the following, we briefly examine relevant aspects of the **reverse engineered binary** and
discuss its improper handling of buffer sizes that culminates in the stack buffer overflow we
intend to exploit.
In the following, we examine some excerpts from the **reverse engineered binary** and discuss its
improper handling of buffer sizes that culminates in the stack buffer overflow we intend to exploit.
Figure 1 shows the de-compiled pseudo C-code that deals with the reading and parsing of file
Figure 1 shows the de-compiled pseudo C-code that deals with the **reading and parsing** of file
`/tmp/circleinfo.txt` - a copy of the downloaded file as mentioned in the previous section. Using
the *libc* function `fgets`, the file's content is read line-by-line into a stack buffer (here
called `line`) of size 1024 (0x400). Using the *libc* function `sscanf`, each read line is then
split into two strings (space-separated), which are copied to stack buffers `db_checksum` and
`db_checksum_val` respectively.
`db_checksum_val`, respectively. As long as the string in buffer `db_checksum` is not equal to
"db_checksum" (`strcmp`), we move on to the next line in the file, if any. The buffer `line` may
therefore contain a maximum of 1023 characters (plus a terminating null-byte).
<hr>
<figure>
<img src="../images/RE_Vuln_02.svg" alt="Reading and parsing file content"/>
<figcaption>
Figure 1: Reverse Engineering - Reading file contents line-by-line and parsing to two strings per line.
Figure 1: Reverse Engineering - Read file contents line-by-line and split each line into two strings.
</figcaption>
</figure>
<hr>
As can be seen in Figure 2 below, stack buffers `db_checksum` and `db_checksum_val`, however, only
have a size of 256 bytes each. A line e.g. consisting of the string `"A"*1021 + " X"` (plus a null
or newline character) will therefore lead to a stack buffer overflow (of buffer `db_checksum` in
the listed example string).
have a size of 256 bytes each. A line e.g. consisting of the string `"A"*1021 + " X"` will therefore
lead to a stack buffer overflow (of buffer `db_checksum` in the listed example string).
<hr>
<figure>
<img src="../images/RE_Vuln_01.svg" alt="Initializing of stack buffers"/>