Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -7,9 +7,9 @@
|
||||
|
||||
- In C and C++, the programmer performs memory management
|
||||
- Flexible, powerful, fast but dangerous
|
||||
- Buffer Overruns
|
||||
- Stack Overruns
|
||||
- Heap Overruns
|
||||
- Buffer Overruns
|
||||
- Stack Overruns
|
||||
- Heap Overruns
|
||||
- Memory-managed languages avoid this, but of course may have their own vulnerabilities
|
||||
|
||||
### Buffer Overflows
|
||||
@@ -51,7 +51,7 @@ void main()
|
||||
###### Stack Smashing
|
||||
|
||||
- In C and C++, low level functions like `strcpy` perform no bounds checking at all
|
||||
- This is partly due to the fact strings are null terminated, if we provide no null character `strcpy` will continue to run
|
||||
- This is partly due to the fact strings are null terminated, if we provide no null character `strcpy` will continue to run
|
||||
- If `str` is long, we can write into other memory
|
||||
|
||||
```c
|
||||
@@ -68,7 +68,7 @@ void function(char *str)
|
||||
|
||||
###### Stack Canaries
|
||||
|
||||
- Stack canaries modify the prologue and epilogue of all functions to check a value ion front of the return address is unchanged
|
||||
- Stack canaries modify the prologue and epilogue of all functions to check a value in front of the return address is unchanged
|
||||
|
||||

|
||||
|
||||
@@ -77,7 +77,7 @@ void function(char *str)
|
||||
###### Data Execution Prevention (NX)
|
||||
|
||||
- Modern operating systems will mark the stack as non-executable
|
||||
- `NX` on AMD, `XD` on Intel and `XN` on arm
|
||||
- `NX` on AMD, `XD` on Intel and `XN` on ARM
|
||||
- An `NX` stack means that adding in our exploit code won’t work
|
||||
- We can circumvent this using a `return-to-libc` attack
|
||||
|
||||
@@ -85,12 +85,12 @@ void function(char *str)
|
||||
|
||||
- To defeat `ret2lib2` various `0x0` null bytes are inserted into standard library addresses
|
||||
- Developers also restrict access to obvious system calls
|
||||
- Address Space Layout Randomisation (`ASLR`) moves the address of library and programs around
|
||||
- They don’t have to move too much before your hand-crafted `ret` addresses will break
|
||||
- Address Space Layout Randomisation (`ASLR`) moves the addresses of libraries and programs around
|
||||
- They don’t have to move too much before your hand-crafted `ret` addresses will break
|
||||
|
||||
###### Return-Oriented Programming
|
||||
|
||||
- Lets forget about injecting code, how about just using existing code in the actual exploitable program
|
||||
- Let’s forget about injecting code, how about just using existing code in the actual exploitable program
|
||||
- No individual section of this program will do what we want
|
||||
- Find short sections, *gadgets* and link them together
|
||||
|
||||
@@ -109,13 +109,13 @@ void function(char *str)
|
||||
##### Heartbleed
|
||||
|
||||
- Heartbleed is a bug in `OpenSSL`
|
||||
- Open source `SSL` library
|
||||
- Started in `OpenBSD`
|
||||
- Used almost *everywhere*
|
||||
- Open source `SSL` library
|
||||
- Started in `OpenBSD`
|
||||
- Used almost *everywhere*
|
||||
- Specifically targeted the heartbeat extension
|
||||
- Extension to regular `SSL` and used for keep-alive purposes, to stop quiet connections being closed
|
||||
- Client sends a message to the server to say it’s alive
|
||||
- Server responds (also alive)
|
||||
- Extension to regular `SSL` and used for keep-alive purposes, to stop quiet connections being closed
|
||||
- Client sends a message to the server to say it’s alive
|
||||
- Server responds (also alive)
|
||||
|
||||

|
||||
|
||||
@@ -142,6 +142,6 @@ if (r >= 0 && s->msg_callback)
|
||||
s, s->msg_callback_arg);
|
||||
```
|
||||
|
||||
This bug would just memcpy a bunch of the server’s ram and send it back to the client. This can expose RSA keys.
|
||||
This bug would just memcpy a bunch of the server’s RAM and send it back to the client. This can expose RSA keys.
|
||||
|
||||
This is called a **buffer overread** attack.
|
||||
This is called a **buffer overread** attack.
|
||||
Reference in new issue
Block a user