بخش پونزدهم بافر اورفلو
ابزارها و فازینگ یا fuzzing برای یافتن باگ
معرفی ابزارهای اصلی فازینگ و روش ساخت یک harness ساده که بافر اورفلوها رو پیدا کنه
توضیح:
fuzzing
یعنی دادن ورودی های خودکار و نامنظم به برنامه برای پیدا کردن کرش یا رفتار غیرعادی
ابزارهای معروف شامل AFL libFuzzer honggfuzz و radamsa هستند
AddressSanitizer
کمک میکنه خطاهای حافظه رو با گزارش دقیق نشون بده
فایل harness
این فایل یک برنامه ساده میسازه که ورودی رو از stdin میخونه و روی بافر محلی کپی میکنه تا برای fuzz مناسب باشه
هدف اینه که fuzzers بتونه ورودی های مختلف رو ارسال کنه و ASan یا کرش رو بگیره
فایل file8_harness.c
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
int main(void) {
char buf[64];
size_t n = fread(buf, 1, sizeof(buf), stdin);
/* ensure null termination for printing */
if (n >= sizeof(buf)) n = sizeof(buf)-1;
buf[n] = '\\0';
/* intentionally unsafe copy to demonstrate overflow during fuzzing */
char target[32];
strcpy(target, buf);
printf("ok got %zu bytes\\n", n);
return 0;
}
دستورات برای کامپایل با AddressSanitizer
با ASan وقتی overflow اتقاق میوفته
دستورات
gcc -g -O1 -fsanitize=address -fno-omit-frame-pointer file8_harness.c -o file8_asan
./file8_asan < some_input
استفاده AFL
AFL
نیاز به یک binary instrumented شده داره و دایرکتوری seed برای ورودی های اولیه
اول نسخه ای با afl-gcc یا afl-clang بسازید بعد fuzz رو اجرا کنید
دستورات AFL
# ساخت با afl
afl-clang-fast -g file8_harness.c -o file8_afl
# آماده سازی دایرکتوری seed
mkdir in
echo "test" > in/seed1
# اجرای afl
afl-fuzz -i in -o out -- ./file8_afl
نکته درباره libFuzzer و clang
برای libFuzzer باید harness با تابع LLVMFuzzerTestOneInput باشه و با clang و -fsanitize=fuzzer ساخته بشه
این روش برای پروژه هایی که library oriented اند مناسب تره
نکته درباره radamsa
radamsa
میتونه seed های تصادفی تولید کنه و با pipe به برنامه ارسال کنه
مثال
radamsa in/seed1 | ./file8_asan
Part 15 Buffer Overflow
Tools and Fuzzing to Find Bugs
Introduction to the main fuzzing tools and how to build a simple harness that finds buffer overflows
Explanation:
Fuzzing
means giving automatic and irregular inputs to the program to find crashes or unusual behavior
Popular tools include AFL libFuzzer honggfuzz and radamsa
AddressSanitizer
Helps show memory errors with detailed reporting
Harness file
This file creates a simple program that reads input from stdin and copies it to a local buffer suitable for fuzzing
The goal is to allow fuzzers to send various inputs and get ASan or crashes
File file8_harness.c
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
int main(void) {
char buf[64];
size_t n = fread(buf, 1, sizeof(buf), stdin);
/* ensure null termination for printing */
if (n >= sizeof(buf)) n = sizeof(buf)-1;
buf[n] = '\\0';
/* intentionally unsafe copy to demonstrate overflow during fuzzing */
char target[32];
strcpy(target, buf);
printf("ok got %zu bytes\\n", n);
return 0;
}
Commands to compile with AddressSanitizer
With ASan when overflow occurs
Commands
gcc -g -O1 -fsanitize=address -fno-omit-frame-pointer file8_harness.c -o file8_asan
./file8_asan < some_input
Using AFL
AFL
requires an instrumented binary and a seed directory for initial inputs
First build with afl-gcc or afl-clang then run fuzz
AFL Commands
# Build with afl
afl-clang-fast -g file8_harness.c -o file8_afl
# Prepare seed directory
mkdir in
echo "test" > in/seed1
# Run afl
afl-fuzz -i in -o out -- ./file8_afl
Note about libFuzzer and clang
For libFuzzer you need harness with function LLVMFuzzerTestOneInput and build with clang and -fsanitize=fuzzer
This method is more suitable for library oriented projects
Note about radamsa
radamsa
Can generate random seeds and send them to the program via pipe
Example
radamsa in/seed1 | ./file8_asan
@reverseengine
❤2👍1
Ghidra Plugin Development for Vulnerability Research
https://www.somersetrecon.com/blog/2019/ghidra-plugin-development-for-vulnerability-research-part-1
@reverseengine
https://www.somersetrecon.com/blog/2019/ghidra-plugin-development-for-vulnerability-research-part-1
@reverseengine
Somerset Recon
Ghidra Plugin Development for Vulnerability Research - Part-1 — Somerset Recon
Overview On March 5th at the RSA security conference, the National Security Agency (NSA) released a reverse engineering tool called Ghidra. Similar to IDA Pro, Ghidra is a disassembler and decompiler with many powerful features (e.g., plugin support,…
❤1
User-Friendly Fuzzing with Sienna Locomotive
https://blog.trailofbits.com/2019/04/08/user-friendly-fuzzing-with-sienna-locomotive
@reverseengine
https://blog.trailofbits.com/2019/04/08/user-friendly-fuzzing-with-sienna-locomotive
@reverseengine
The Trail of Bits Blog
User-Friendly Fuzzing with Sienna Locomotive
Fuzzing is a great way to find bugs in software, but many developers don’t use it. We hope to change that today with the release of Sienna Locomotive, a new open-source fuzzer for Windows that emphasizes usability. Sienna Locomotive aims to make fuzzing accessible…
❤1
ROP Gadget
وقتی NX جلوی اجرای Shellcode رو گرفت اکسپلویترها فهمیدن یه چیز مهم وجود داره:
داخل هر برنامه و کتابخونه کلی کد آماده هست.
آیا میشه همین کدهای آماده رو به شکل دلخواه اجرا کرد؟
بله و به این میگن ROP
Gadget?
Gadget
یه تیکه کد خیلی کوچیکه که از قبل داخل باینری وجود داره اخرش معمولا ret داره
مثلا:
Copy code
یا:
Copy code
اینها به تنهایی کار بزرگی نمیکنن ولی وقتی پشت سر هم قرار بگیرن تبدیل میشن به یه برنامه کامل
چرا ret مهمه؟
چون ret ادرس بعدی رو از استک برمیداره و میره اجراش میکنه
یعنی اگر استک رو کنترل کنید میتونید تعیین کنی بعد از هر gadget کجا بره
در نتیجه:
RIP → gadget اول
ret → gadget دوم
ret → gadget سوم
و همینطور ادامه پیدا میکنه
CPU
عملاً داره برنامهای رو اجرا میکنه که شما از روی استک نوشتید
ROP Chain?
ROP Chain
یعنی یه لیست از آدرس gadget ها که روی استک میذارید
مثلا مفهومش اینه:
Copy code
یعنی:
مقدار ارگومان ست میشه بعد تابع اجرا میشه
بدون اینکه حتی یک بایت کد جدید اجرا کرده باشید
چرا ROP اینقدر قدرتمنده؟
چون:
NX رو دور میزنه
از کد trusted استفاده میکنه تقریبا روی هر برنامهای قابل انجامه پایهی خیلی از exploitهای واقعی دنیاست
بیشتر حملات مدرن عملا یه نوع ROP هستن
یک نکته خیلی مهم که تازه کارها نمیفهمن
ROP
یعنی کد ننویسید جریان اجرای CPU رو با قطعات آماده بسازید
شما دارید CPU رو گول میزنید که فکر کنه این مسیر طبیعی برنامست
ROP Gadget
When NX stopped Shellcode execution, the exploiters realized something important:
There is a whole bunch of ready-made code inside every program and library.
Can this ready-made code be executed in any way you want?
Yes, and this is called a ROP
Gadget?
Gadget
A very small piece of code that is already inside the binary, usually with ret at the end
For example:
Copy code
or:
Copy code
These don't do much on their own, but when they are put together, they become a complete program
Why is ret important?
Because ret takes the next address from the stack and executes it
That is, if you control the stack, you can determine where it goes after each gadget
As a result:
RIP → first gadget
ret → second gadget
ret → third gadget
And so on
The CPU
is actually executing the program that you wrote from the stack
ROP Chain?
ROP Chain
That is, a list of gadget addresses that you put on the stack
For example, its meaning is:
Copy code
That is:
The value of the argument is set, then the function is executed
Without you executing a single new byte of code
Why is ROP so powerful?
Because:
Bypasses NX
Uses trusted code Can be executed on almost any program Is the basis of many real world exploits
Most modern attacks are actually a type of ROP
A very important point that beginners don't understand
ROP
means don't write code Build the CPU execution flow with ready-made parts
You are tricking the CPU into thinking that this is the natural path of the program
@reverseengine
وقتی NX جلوی اجرای Shellcode رو گرفت اکسپلویترها فهمیدن یه چیز مهم وجود داره:
داخل هر برنامه و کتابخونه کلی کد آماده هست.
آیا میشه همین کدهای آماده رو به شکل دلخواه اجرا کرد؟
بله و به این میگن ROP
Gadget?
Gadget
یه تیکه کد خیلی کوچیکه که از قبل داخل باینری وجود داره اخرش معمولا ret داره
مثلا:
Copy code
pop rdi
ret
یا:
Copy code
mov rax, rdi
ret
اینها به تنهایی کار بزرگی نمیکنن ولی وقتی پشت سر هم قرار بگیرن تبدیل میشن به یه برنامه کامل
چرا ret مهمه؟
چون ret ادرس بعدی رو از استک برمیداره و میره اجراش میکنه
یعنی اگر استک رو کنترل کنید میتونید تعیین کنی بعد از هر gadget کجا بره
در نتیجه:
RIP → gadget اول
ret → gadget دوم
ret → gadget سوم
و همینطور ادامه پیدا میکنه
CPU
عملاً داره برنامهای رو اجرا میکنه که شما از روی استک نوشتید
ROP Chain?
ROP Chain
یعنی یه لیست از آدرس gadget ها که روی استک میذارید
مثلا مفهومش اینه:
Copy code
offset
addr(pop rdi)
value("/bin/sh")
addr(system)
یعنی:
مقدار ارگومان ست میشه بعد تابع اجرا میشه
بدون اینکه حتی یک بایت کد جدید اجرا کرده باشید
چرا ROP اینقدر قدرتمنده؟
چون:
NX رو دور میزنه
از کد trusted استفاده میکنه تقریبا روی هر برنامهای قابل انجامه پایهی خیلی از exploitهای واقعی دنیاست
بیشتر حملات مدرن عملا یه نوع ROP هستن
یک نکته خیلی مهم که تازه کارها نمیفهمن
ROP
یعنی کد ننویسید جریان اجرای CPU رو با قطعات آماده بسازید
شما دارید CPU رو گول میزنید که فکر کنه این مسیر طبیعی برنامست
ROP Gadget
When NX stopped Shellcode execution, the exploiters realized something important:
There is a whole bunch of ready-made code inside every program and library.
Can this ready-made code be executed in any way you want?
Yes, and this is called a ROP
Gadget?
Gadget
A very small piece of code that is already inside the binary, usually with ret at the end
For example:
Copy code
pop rdi
ret
or:
Copy code
mov rax, rdi
ret
These don't do much on their own, but when they are put together, they become a complete program
Why is ret important?
Because ret takes the next address from the stack and executes it
That is, if you control the stack, you can determine where it goes after each gadget
As a result:
RIP → first gadget
ret → second gadget
ret → third gadget
And so on
The CPU
is actually executing the program that you wrote from the stack
ROP Chain?
ROP Chain
That is, a list of gadget addresses that you put on the stack
For example, its meaning is:
Copy code
offset
addr(pop rdi)
value("/bin/sh")
addr(system)
That is:
The value of the argument is set, then the function is executed
Without you executing a single new byte of code
Why is ROP so powerful?
Because:
Bypasses NX
Uses trusted code Can be executed on almost any program Is the basis of many real world exploits
Most modern attacks are actually a type of ROP
A very important point that beginners don't understand
ROP
means don't write code Build the CPU execution flow with ready-made parts
You are tricking the CPU into thinking that this is the natural path of the program
@reverseengine
❤4
How to bypass Instagram SSL Pinning on Android (v78)
https://plainsec.org/how-to-bypass-instagram-ssl-pinning-on-android-v78
@reverseengine
https://plainsec.org/how-to-bypass-instagram-ssl-pinning-on-android-v78
@reverseengine
❤2
Heap Exploitation series:
Understanding the Glibc Heap:
Free, Bins, Tcache
https://azeria-labs.com/heap-exploitation-part-2-glibc-heap-free-bins
@reverseengine
Understanding the Glibc Heap:
Free, Bins, Tcache
https://azeria-labs.com/heap-exploitation-part-2-glibc-heap-free-bins
@reverseengine
Azeria-Labs
Heap Exploitation Part 2: Understanding the Glibc Heap Implementation
❤3
Generate DLL proxy/sideload projects. Automatically parses PE export tables and generates ready-to-compile project for red team engagements
https://github.com/Whitecat18/LazyDLLSideload
@reverseengine
https://github.com/Whitecat18/LazyDLLSideload
@reverseengine
GitHub
GitHub - Whitecat18/LazyDLLSideload: Generate DLL proxy/sideload projects. Automatically parses PE export tables and generates…
Generate DLL proxy/sideload projects. Automatically parses PE export tables and generates ready-to-compile project for red team engagements. - Whitecat18/LazyDLLSideload
❤2
Someone published the source code of the GAPZ bootkit:
Bootkit: https://github.com/Darkabode/zerokit
Usermode Part: https://github.com/Darkabode/possessor
Server Controller Part: https://github.com/Darkabode/0ctrl
Some shared Code: https://github.com/Darkabode/0lib
Analysis GAPZ Bootkit: https://www.welivesecurity.com/wp-content/uploads/2013/04/gapz-bootkit-whitepaper.pdf
@reverseengine
Bootkit: https://github.com/Darkabode/zerokit
Usermode Part: https://github.com/Darkabode/possessor
Server Controller Part: https://github.com/Darkabode/0ctrl
Some shared Code: https://github.com/Darkabode/0lib
Analysis GAPZ Bootkit: https://www.welivesecurity.com/wp-content/uploads/2013/04/gapz-bootkit-whitepaper.pdf
@reverseengine
GitHub
GitHub - Darkabode/zerokit: Zerokit/GAPZ rootkit (non buildable and only for researching)
Zerokit/GAPZ rootkit (non buildable and only for researching) - Darkabode/zerokit
❤2
Linux Kernel Exploitation
https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x1-smashing.html?m=1
@reverseengine
https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x1-smashing.html?m=1
@reverseengine
❤2
Hack-cessibility: When DLL Hijacks Meet Windows Helpers
https://trustedsec.com/blog/hack-cessibility-when-dll-hijacks-meet-windows-helpers
@reverseengine
https://trustedsec.com/blog/hack-cessibility-when-dll-hijacks-meet-windows-helpers
@reverseengine
TrustedSec
Hack-cessibility: When DLL Hijacks Meet Windows Helpers
❤4
The art of Breaking Through
https://0xdbgman.github.io/posts/sec-controls-the-art-of-breaking-through
@reverseengine
https://0xdbgman.github.io/posts/sec-controls-the-art-of-breaking-through
@reverseengine
DbgMan
Security Controls: Modern EDR & Windows Protection Bypass
Red Teamer & Low-Level Developer. Deep dives into Windows Internals, Kernel Exploitation, Driver Analysis, and Red Team techniques.
❤4
EDR Killer
Exploits a vulnerability in the wsftprm.sys driver to disable antivirus and EDR
https://github.com/ThanniKudam/TopazTerminator
@reverseengine
Exploits a vulnerability in the wsftprm.sys driver to disable antivirus and EDR
https://github.com/ThanniKudam/TopazTerminator
@reverseengine
GitHub
GitHub - ThanniKudam/TopazTerminator: Just another EDR killer
Just another EDR killer. Contribute to ThanniKudam/TopazTerminator development by creating an account on GitHub.
❤7
متاسفانه طی اتفاقات اخیر پوریا دیگه بینمون نیست
دانشجوی عزیز و مهربون و با پشتکار
نامت تا ابد پیش هممون جاودانه
روحت در ارامش داداش دلمون برات تنگ میشه
پوریای عزیزم هنوز باور ندارم که رفتی
به احترام پوریا فعالیت کانال رو ی کم با تاخیر شروع میکنیم
هیچ وقت فراموشت نمیکنیم برادر 💔
@p0or1ya
Unfortunately, due to recent events, Pouria is no longer with us.
Dear, kind and diligent student
Your name will be immortal to all of us forever
May your soul rest in peace, brother, we miss you
My dear Pouria, I still can't believe you're gone
Out of respect for Pouria, we will start the channel's activity with a slight delay.
We will never forget you, brother.
R. I. P. 🖤
@p0or1ya
دانشجوی عزیز و مهربون و با پشتکار
نامت تا ابد پیش هممون جاودانه
روحت در ارامش داداش دلمون برات تنگ میشه
پوریای عزیزم هنوز باور ندارم که رفتی
به احترام پوریا فعالیت کانال رو ی کم با تاخیر شروع میکنیم
هیچ وقت فراموشت نمیکنیم برادر 💔
@p0or1ya
Unfortunately, due to recent events, Pouria is no longer with us.
Dear, kind and diligent student
Your name will be immortal to all of us forever
May your soul rest in peace, brother, we miss you
My dear Pouria, I still can't believe you're gone
Out of respect for Pouria, we will start the channel's activity with a slight delay.
We will never forget you, brother.
R. I. P. 🖤
@p0or1ya
💔30😭2
سیستم عامل چجوری کار میکنه؟
یک برنامه در حال اجرا یک کار بسیار ساده رو انجام میده دستور ها رو دنبال میکنه میلیون ها و حتی میلیارد ها بار در هر ثانیه CPU یک دستور رو از حافظه میگیره و اونو رمزگشایی میکنه یعنی میفهمه کدوم دستور هست و اونو اجرا میکنه یعنی کاری که قراره انجام بشه مثل جمع کردن دو عدد با هم دسترسی به حافظه بررسی یک شرط پرش به یک تابع انجام میده بعد از تموم شدن کار با این دستور CPU به دستور بعدی میره و به همین ترتیب تا زمانی که برنامه کامل بشه
How does an operating system work?
A running program does a very simple job It follows instructions Millions and even billions of times per second, the CPU fetches an instruction from memory and decodes it meaning it understands what the instruction is and executes it meaning it does what it is supposed to do such as adding two numbers together accessing memory checking a condition jumping to a function and after it finishes working with this instruction the CPU moves on to the next instruction and so on until the program is complete
@reverseengine
یک برنامه در حال اجرا یک کار بسیار ساده رو انجام میده دستور ها رو دنبال میکنه میلیون ها و حتی میلیارد ها بار در هر ثانیه CPU یک دستور رو از حافظه میگیره و اونو رمزگشایی میکنه یعنی میفهمه کدوم دستور هست و اونو اجرا میکنه یعنی کاری که قراره انجام بشه مثل جمع کردن دو عدد با هم دسترسی به حافظه بررسی یک شرط پرش به یک تابع انجام میده بعد از تموم شدن کار با این دستور CPU به دستور بعدی میره و به همین ترتیب تا زمانی که برنامه کامل بشه
How does an operating system work?
A running program does a very simple job It follows instructions Millions and even billions of times per second, the CPU fetches an instruction from memory and decodes it meaning it understands what the instruction is and executes it meaning it does what it is supposed to do such as adding two numbers together accessing memory checking a condition jumping to a function and after it finishes working with this instruction the CPU moves on to the next instruction and so on until the program is complete
@reverseengine
❤3
مجازی سازی:
سیستم عامل یک منبع فیزیکی مثل CPU یا حافظه یا دیسک رو میگیره و اونو به شکل مجازی عمومی تر قدرتمند تر و اسون برای استفاده خودش تبدیل میکنه
Virtualization:
The operating system takes a physical resource such as a processor or disk or storage and converts it into a more general powerful and easier-to-use virtual form
@reverseengine
سیستم عامل یک منبع فیزیکی مثل CPU یا حافظه یا دیسک رو میگیره و اونو به شکل مجازی عمومی تر قدرتمند تر و اسون برای استفاده خودش تبدیل میکنه
Virtualization:
The operating system takes a physical resource such as a processor or disk or storage and converts it into a more general powerful and easier-to-use virtual form
@reverseengine
همزمانی:
مجموعه ای از مشکلات وقتی که کار روی چند تا چیز به طور همزمان در یک برنامه واحد اجرا میشن و باید مدام اونها رو چک کنیم
Concurrency: A set of problems that arise when multiple things are being worked on simultaneously in a single program and we need to keep checking them
@reverseengine
مجموعه ای از مشکلات وقتی که کار روی چند تا چیز به طور همزمان در یک برنامه واحد اجرا میشن و باید مدام اونها رو چک کنیم
Concurrency: A set of problems that arise when multiple things are being worked on simultaneously in a single program and we need to keep checking them
@reverseengine
فرایند (process):
یک برنامه در حال اجرا فقط روی دیسک قرار میگیره سیستم عامل بایت ها رو میگیره و اجرا میکنه و برنامه رو به چیز مفیدی تبدیل میکنه
Process:
A running program simply sits on disk The operating system takes the bytes and executes them turning the program into something useful
@reverseengine
یک برنامه در حال اجرا فقط روی دیسک قرار میگیره سیستم عامل بایت ها رو میگیره و اجرا میکنه و برنامه رو به چیز مفیدی تبدیل میکنه
Process:
A running program simply sits on disk The operating system takes the bytes and executes them turning the program into something useful
@reverseengine
ما یک اصطلاح جالب داریم به نام توهم چند cpu
سیستم عامل با مجازیسازی cpu این توهم رو ایجاد میکنه که با اجرای یک فرایند و متوقف کردن اون و اجرای فرایند دیگه و غیره سیستم عامل میتونه این توهم رو ایجاد کنه که cpu های مجازی زیادی وجود داره در حالی که فقط یک یا چند cpu فیزیکی وجود داره این تکنیک اساسی به عنوان اشتراک زمانی شناخته میشه
We have an interesting term called the illusion of multiple CPUs
The operating system creates this illusion by virtualizing CPUs By running one process stopping it, running another process and so on the operating system can create the illusion that there are many virtual CPUs when there is only one or a few physical CPUs This basic technique is known as time-sharing
@reverseengine
سیستم عامل با مجازیسازی cpu این توهم رو ایجاد میکنه که با اجرای یک فرایند و متوقف کردن اون و اجرای فرایند دیگه و غیره سیستم عامل میتونه این توهم رو ایجاد کنه که cpu های مجازی زیادی وجود داره در حالی که فقط یک یا چند cpu فیزیکی وجود داره این تکنیک اساسی به عنوان اشتراک زمانی شناخته میشه
We have an interesting term called the illusion of multiple CPUs
The operating system creates this illusion by virtualizing CPUs By running one process stopping it, running another process and so on the operating system can create the illusion that there are many virtual CPUs when there is only one or a few physical CPUs This basic technique is known as time-sharing
@reverseengine
مکانیسم ها:
روش ها یا پروتوکول های سطح پایینی هستند که یک قطعه مورد نیاز رو پیاده سازی میکنن
Mechanisms:
are low-level methods or protocols that implement a required component
@reverseengine
روش ها یا پروتوکول های سطح پایینی هستند که یک قطعه مورد نیاز رو پیاده سازی میکنن
Mechanisms:
are low-level methods or protocols that implement a required component
@reverseengine