Update Vulnerability Characteristics section

This commit is contained in:
Damian Pfammatter
2024-04-25 15:48:58 +02:00
parent 615efa000f
commit 9f2207d945
+15 -13
View File
@@ -30,7 +30,7 @@ how they might first help us to build a proof-of-concept (PoC) exploit, which we
a powerful exploit, giving us a **reverse shell** on the targeted devices.
The first module, `morion_control_hijacker`, allows us to detect situations, where registers that
might influence the control-flow (typically the *PC* register), get a value assigned that relies on
might influence the control-flow (typically the *pc* register), get a value assigned that relies on
a symbolic variable. Since symbolic variables typically are assigned to inputs an attacker controls,
the module helps to identify and reason about **control-flow hijacking** conditions.
@@ -43,11 +43,12 @@ must be to trigger it.
## Analysis Module morion_control_hijacker
In the following, we use and analyze the concrete execution trace we recorded in
[Tracing: Run](./3_tracing.md#run). Remember that the trace has been stored to a file named
`circled.yaml` and recorded the instructions executed while the binary `circled` processed the file
`circleinfo.txt`, which contained the proof-of-vulnerability (PoV) payload `"A"*1021 + " X"`.
`circled.yaml` and recorded the instructions of binary `circled`, while processing the file
`circleinfo.txt`. The file `circleinfo.txt` contained the proof-of-vulnerability (PoV) payload
`"A"*1021 + " X"`.
### Vulnerability Characteristics
Let's use [Morion](https://github.com/pdamian/morion)'s analysis module `morion_control_hijacker`
with the aforementioned trace as input and review its output.
Let's begin by using [Morion](https://github.com/pdamian/morion)'s analysis module
`morion_control_hijacker`, with the aforementioned trace as input and review its output.
`morion_control_hijacker circled.yaml`:
```
@@ -74,12 +75,13 @@ Type quit(), exit() or ctrl-d to leave the interpreter.
In [1]:
```
[Morion](https://github.com/pdamian/morion) stops after a `pop{..., pc}` instruction at address
`0xcf24` and prints the following message: `Potential control hijack due to unrestricted register
'pc'`. This means that register *PC* is based on some symbolic variable(s), i.e. in our specific
example, is somehow influenced by contents originating from file `circleinfo.txt`.
[Morion](https://github.com/pdamian/morion) stops after the `pop` instruction at address `0xcf24`
and prints the message `Potential control hijack due to unrestricted register 'pc'`. This means that
register *pc* is based on some symbolic variable(s), i.e. in our specific example, is somehow
influenced by contents originating from file `circleinfo.txt`.
[Morion](https://github.com/pdamian/morion) entered an interactive (Python) shell that allows us to
investigate the observed situation. For instance, we can perform a first simple test to check whether we can set the *PC* to a different value:
further investigate the observed situation. For instance, we can perform a first simple test to
check whether we can set the *pc* to a different value:
```python
In [1]: pc_ast = ctx.getRegisterAst(ctx.registers.pc)
@@ -93,7 +95,7 @@ In [3]: pprint(model)
395: 5132;;0xbeffc24f;model;fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0);s+395:8 = 0xa1
}
```
The first command [1] accesses the **abstract syntax tree (AST)** representation of register *PC*.
The first command [1] accesses the **abstract syntax tree (AST)** representation of register *pc*.
In the second command [2] we ask the symbolic execution engine
([Triton](https://triton-library.github.io/)) for a model (or solution) to the expression
`pc_ast == 0xa1a2a3a4`. In other words, we ask what to do, to let the program flow to address
@@ -139,8 +141,8 @@ In [4]: quit
[2024-04-11 11:38:12] [INFO] Start storing file 'circled.yaml'...
[2024-04-11 11:38:12] [INFO] ... finished storing file 'circled.yaml'.
```
At this point we learned, that registers *R4*-*R11*, as well as the *PC* are based on symbolic
variables that an attacker might control. We further verified that we can modify the *PC* to point
At this point we learned, that registers *r4*-*r11*, as well as the *pc* are based on symbolic
variables that an attacker might control. We further verified that we can modify the *pc* to point
to another value.
### Return Oriented Programming (ROP)
- design a simple ROP chain (crashing the binary)