mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
Update Vulnerability Characteristics section
This commit is contained in:
+15
-13
@@ -30,7 +30,7 @@ how they might first help us to build a proof-of-concept (PoC) exploit, which we
|
||||
a powerful exploit, giving us a **reverse shell** on the targeted devices.
|
||||
|
||||
The first module, `morion_control_hijacker`, allows us to detect situations, where registers that
|
||||
might influence the control-flow (typically the *PC* register), get a value assigned that relies on
|
||||
might influence the control-flow (typically the *pc* register), get a value assigned that relies on
|
||||
a symbolic variable. Since symbolic variables typically are assigned to inputs an attacker controls,
|
||||
the module helps to identify and reason about **control-flow hijacking** conditions.
|
||||
|
||||
@@ -43,11 +43,12 @@ must be to trigger it.
|
||||
## Analysis Module morion_control_hijacker
|
||||
In the following, we use and analyze the concrete execution trace we recorded in
|
||||
[Tracing: Run](./3_tracing.md#run). Remember that the trace has been stored to a file named
|
||||
`circled.yaml` and recorded the instructions executed while the binary `circled` processed the file
|
||||
`circleinfo.txt`, which contained the proof-of-vulnerability (PoV) payload `"A"*1021 + " X"`.
|
||||
`circled.yaml` and recorded the instructions of binary `circled`, while processing the file
|
||||
`circleinfo.txt`. The file `circleinfo.txt` contained the proof-of-vulnerability (PoV) payload
|
||||
`"A"*1021 + " X"`.
|
||||
### Vulnerability Characteristics
|
||||
Let's use [Morion](https://github.com/pdamian/morion)'s analysis module `morion_control_hijacker`
|
||||
with the aforementioned trace as input and review its output.
|
||||
Let's begin by using [Morion](https://github.com/pdamian/morion)'s analysis module
|
||||
`morion_control_hijacker`, with the aforementioned trace as input and review its output.
|
||||
|
||||
`morion_control_hijacker circled.yaml`:
|
||||
```
|
||||
@@ -74,12 +75,13 @@ Type quit(), exit() or ctrl-d to leave the interpreter.
|
||||
|
||||
In [1]:
|
||||
```
|
||||
[Morion](https://github.com/pdamian/morion) stops after a `pop{..., pc}` instruction at address
|
||||
`0xcf24` and prints the following message: `Potential control hijack due to unrestricted register
|
||||
'pc'`. This means that register *PC* is based on some symbolic variable(s), i.e. in our specific
|
||||
example, is somehow influenced by contents originating from file `circleinfo.txt`.
|
||||
[Morion](https://github.com/pdamian/morion) stops after the `pop` instruction at address `0xcf24`
|
||||
and prints the message `Potential control hijack due to unrestricted register 'pc'`. This means that
|
||||
register *pc* is based on some symbolic variable(s), i.e. in our specific example, is somehow
|
||||
influenced by contents originating from file `circleinfo.txt`.
|
||||
[Morion](https://github.com/pdamian/morion) entered an interactive (Python) shell that allows us to
|
||||
investigate the observed situation. For instance, we can perform a first simple test to check whether we can set the *PC* to a different value:
|
||||
further investigate the observed situation. For instance, we can perform a first simple test to
|
||||
check whether we can set the *pc* to a different value:
|
||||
```python
|
||||
In [1]: pc_ast = ctx.getRegisterAst(ctx.registers.pc)
|
||||
|
||||
@@ -93,7 +95,7 @@ In [3]: pprint(model)
|
||||
395: 5132;;0xbeffc24f;model;fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0);s+395:8 = 0xa1
|
||||
}
|
||||
```
|
||||
The first command [1] accesses the **abstract syntax tree (AST)** representation of register *PC*.
|
||||
The first command [1] accesses the **abstract syntax tree (AST)** representation of register *pc*.
|
||||
In the second command [2] we ask the symbolic execution engine
|
||||
([Triton](https://triton-library.github.io/)) for a model (or solution) to the expression
|
||||
`pc_ast == 0xa1a2a3a4`. In other words, we ask what to do, to let the program flow to address
|
||||
@@ -139,8 +141,8 @@ In [4]: quit
|
||||
[2024-04-11 11:38:12] [INFO] Start storing file 'circled.yaml'...
|
||||
[2024-04-11 11:38:12] [INFO] ... finished storing file 'circled.yaml'.
|
||||
```
|
||||
At this point we learned, that registers *R4*-*R11*, as well as the *PC* are based on symbolic
|
||||
variables that an attacker might control. We further verified that we can modify the *PC* to point
|
||||
At this point we learned, that registers *r4*-*r11*, as well as the *pc* are based on symbolic
|
||||
variables that an attacker might control. We further verified that we can modify the *pc* to point
|
||||
to another value.
|
||||
### Return Oriented Programming (ROP)
|
||||
- design a simple ROP chain (crashing the binary)
|
||||
|
||||
Reference in New Issue
Block a user