This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+17 -17
View File
@@ -7,9 +7,9 @@
- In C and C++, the programmer performs memory management
- Flexible, powerful, fast but dangerous
- Buffer Overruns
- Stack Overruns
- Heap Overruns
- Buffer Overruns
- Stack Overruns
- Heap Overruns
- Memory-managed languages avoid this, but of course may have their own vulnerabilities
### Buffer Overflows
@@ -51,7 +51,7 @@ void main()
###### Stack Smashing
- In C and C++, low level functions like `strcpy` perform no bounds checking at all
- This is partly due to the fact strings are null terminated, if we provide no null character `strcpy` will continue to run
- This is partly due to the fact strings are null terminated, if we provide no null character `strcpy` will continue to run
- If `str` is long, we can write into other memory
```c
@@ -68,7 +68,7 @@ void function(char *str)
###### Stack Canaries
- Stack canaries modify the prologue and epilogue of all functions to check a value ion front of the return address is unchanged
- Stack canaries modify the prologue and epilogue of all functions to check a value in front of the return address is unchanged
![1646679244.png](img/1646679244.png)
@@ -77,7 +77,7 @@ void function(char *str)
###### Data Execution Prevention (NX)
- Modern operating systems will mark the stack as non-executable
- `NX` on AMD, `XD` on Intel and `XN` on arm
- `NX` on AMD, `XD` on Intel and `XN` on ARM
- An `NX` stack means that adding in our exploit code won’t work
- We can circumvent this using a `return-to-libc` attack
@@ -85,12 +85,12 @@ void function(char *str)
- To defeat `ret2lib2` various `0x0` null bytes are inserted into standard library addresses
- Developers also restrict access to obvious system calls
- Address Space Layout Randomisation (`ASLR`) moves the address of library and programs around
- They don’t have to move too much before your hand-crafted `ret` addresses will break
- Address Space Layout Randomisation (`ASLR`) moves the addresses of libraries and programs around
- They don’t have to move too much before your hand-crafted `ret` addresses will break
###### Return-Oriented Programming
- Lets forget about injecting code, how about just using existing code in the actual exploitable program
- Let’s forget about injecting code, how about just using existing code in the actual exploitable program
- No individual section of this program will do what we want
- Find short sections, *gadgets* and link them together
@@ -109,13 +109,13 @@ void function(char *str)
##### Heartbleed
- Heartbleed is a bug in `OpenSSL`
- Open source `SSL` library
- Started in `OpenBSD`
- Used almost *everywhere*
- Open source `SSL` library
- Started in `OpenBSD`
- Used almost *everywhere*
- Specifically targeted the heartbeat extension
- Extension to regular `SSL` and used for keep-alive purposes, to stop quiet connections being closed
- Client sends a message to the server to say it’s alive
- Server responds (also alive)
- Extension to regular `SSL` and used for keep-alive purposes, to stop quiet connections being closed
- Client sends a message to the server to say it’s alive
- Server responds (also alive)
![1646679952.png](img/1646679952.png)
@@ -142,6 +142,6 @@ if (r >= 0 && s->msg_callback)
s, s->msg_callback_arg);
```
This bug would just memcpy a bunch of the server’s ram and send it back to the client. This can expose RSA keys.
This bug would just memcpy a bunch of the server’s RAM and send it back to the client. This can expose RSA keys.
This is called a **buffer overread** attack.
This is called a **buffer overread** attack.