SlideShare ist ein Scribd-Unternehmen logo
1 von 58
Post exploitation techniques on OSX and Iphone VincenzoIozzo vincenzo.iozzo@zynamics.com
Who I am Student at PolitecnicodiMilano Security Consultant at Secure Network srl Reverse Engineer at zynamics GmbH
Quick overview The old guy:  Userland-exec on OSX Some practical examples The new guy:  Something similar to userland-exec on factory Iphone Proof that it works First step toward Meterpreter on factory iPhone
Mach-O file Header structure: information on the target architecture and options to interpret the file. Load commands: symbol table location, registers state. Segments: define region of the virtual memory, contain sections with code or data.
Mach-O representation
Segment and sections
Let your Mach-O fly! Userland-exec Execute an application without the kernel Technique was presented at BH DC  The first part of this talk covers technique and some applications of it to Mac OS X
WWW Who: an attacker with a remote code execution in his pocket. Where: the attack is two-staged. First run a shellcode to receive the binary, then run the auto-loader contained in the binary. Why: later in this talk.
What kind of binaries? Any Mach-O file, from ls to Safari In real life, probably stuff like keyboard sniffers, other not-so-nice programs
What normally happens You want to run your binary: mybin execve system call is called Kernel parses the binary, maps code and data, and creates a stack for the binary Dyld resolves dependencies and jumps to the binary entry point
What Mach-O on the Fly does Craft a binary which contains a stack identical to the one created by the kernel and a piece of code which mimics the kernel Send binary to exploited process Do some cleanup, jump to the dynamic linker entry point (as the kernel would do)
In a picture
Stack Mach-O file base address Command line arguments Environment variables Execution path All padded
Stack representation
Auto-loader Embedded in binary Impersonates the kernel Un-maps the old binary Maps the new one
Auto-loader description  Parses the binary Reads the virtual addresses of  the injected binary segments Unloads the attacked binary segments pointed by the virtual addresses Loads the injected binary segments
Auto-loader description(2) Maps the crafted stack referenced by __PAGEZERO Cleans registers Cleans some libSystem variables Jumps to dynamic linker entry point
We do like pictures, don’t we? Victim’s process address space TEXT DATA LINKEDIT SEGMENT -N TEXT DATA LINKEDIT SEGMENT-N
Infected binary We need to find a place to store the auto-loader and the crafted stack  __PAGEZERO infection technique Cavity infector technique
PAGEZERO Infection Change __PAGEZERO protection flags with a custom value Store the crafted stack and the auto-loader code at the end of the binary Point __PAGEZERO to the crafted stack Overwrite the first bytes of the file with the auto-loader address
Binary layout MODIFIED HEADER INFECTED __PAGEZERO LOAD COMMANDS AND SEGMENTS SECTIONS AND BINARY DATA SHELLCODE CRAFTED STACK
Let’s clean things up We need to clean up some variables in order to make the attack work They are stored in libSystem They are not exported ASLR for libraries makes this non-trivial No dlopen/dlsym combo
Defeat ASLR using the dynamic linker The dynamic linker has a list of the linked libraries We can access this list by using some of its function  Remember that we want to perform everything in memory
Useful dyld functions _dyld_image_count() used to retrieve the number of linked libraries of a process. _dyld_get_image_header() used to retrieve the base address of each library. _dyld_get_image_name() used to retrieve the name of a given library.
Find ‘em Parse dyld load commands. Retrieve __LINKEDIT address. Iterate dyld symbol table and search for the functions name in __LINKEDIT.
Back to libSystem Non-exported symbols are taken out from the symbol table when loaded. Open libSystem binary, find the variables in the symbol table. Adjust variables to the base address of the in-memory __DATA segment.
Put pieces together Iterate the header structure of libSystem in-memory and find the __DATA base address. __DATA base address 0x2000  Symbol at 0x2054 In-memory __DATA base address 0x4000 Symbol in-memory at 0x4054
Mach-O Fly payload Not much bigger than bind shellcode A lot of work is in preparing the binary to send
Mach-O Fly payload(x86) char shellcode[] = "31c0504050405050b061cd809989c652” "525268000204d289e36a10535652b068” "cd80525652b06acd8052525652b01ecd” "8089c331c0504850b80210000050b807""00000050b9404b4c005131c05050b8c5” "000000cd8089c731c050506a40515753” "53b81d000000cd80578b078d0438ffe0"
Results Execute a binary to an arbitrary machine. No traces on the hard-disk. No execve(), the kernel doesn’t know about us.  It works with every binary. It is possible to write payloads in a high level language.
DEMO
Entering iPhone
Iphone nightmare - first step We (I and Charlie) tried to port my attack to Iphone and we succeeded on jailbroken ones We, as everyone else who tried to write attacks for this OS, were convinced it would have worked on factory phones too
Iphone nightmare – step two  It didn’t. Code signing and XN bit are a huge problem on factory iPhones You cannot execute a page unless is signed You cannot set a page executable if it was writable
My face at this point
A step toward success Just two days before our presentation at BH EU Charlie discovered that it is possible to set execution flags on a writable page But only shared libraries pages
My face after Charlie’s discovery
But still.. My attack could not work anyway cause we cannot touch the executable pages So instead of a binary we decided to inject a library.. .. It worked!
My face at the end
Why so?  Until now there was no way to execute your own code on a factory phone No advanced payloads In most cases no payloads at all Just some very hard return-into-libSystem stuff With this attack we have: Advanced payloads(Meterpreter anyone?) No need to play with return-into-something stuff anymo
A few questions How Charlie’s trick works? How can we map a library? Ok you have an injected library, now what? How do we play with dyld in order to link our library?
How Charlie’s trick works? Three steps:  Call vm_protect() in order to change page permissions to readable and writable Write whatever you want Call vm_protect() again with readable and executable flags
How can we map a library? Mapping a library is no different from mapping an executable We need to make sure to map the injected library upon an already mapped one Clearly we cannot just memcpy() stuff
Leveraging the trick For each segment we need to map we issue a vm_protect with READ and WRITE flags We copy the segment We issue another vm_protect with the protection flags the segment expects
Ok you have an injected library, now what? A non-linked library is useless The linking process is in charge of resolving library dependencies and link the executable to the library We need to work on the dynamic linker in order to understand how to link it
OsxdyldvsiPhonedyld On Osx you have a bunch of ways for linking a library stored in memory None of them work on iPhone (they have taken out the code for doing this)
So how do you load a library on Iphone? The library must be on the disk You need to call dlopen() The library must be signed
But our library is not signed, is it?
What to do now? Dyld has still a way of mapping a binary from memory (it has to for loading the main binary) We should use it But it’s simply not enough
The idea After we mapped the library we call dlopen()  We hijack dlopen() execution in order to call the function which loads a binary from memory A few patches are needed
Dlopen hijacking
Loading from Memory
So we’re done? Not really When the library is linked it searches for symbols in each linked library *each linked library* means even the one we have overwritten
One last patch Before overwriting the victim library we force dlclose() to unlink it To “force” means to ignore the garbage collector for libraries We need to be careful with this one, some frameworks will crash if they are forced to be unloaded
It’s done
Results It is possible to load a arbitrary non-signed library in the address space of an arbitrary process (despite the code signing stuff) It’s the only reliable way to have a working-payloads on factory phones Rooms for improvements Meterpreter anyone?
DEMO
Thanks!Questions?

Weitere ähnliche Inhalte

Was ist angesagt?

Program Structure in GNU/Linux (ELF Format)
Program Structure in GNU/Linux (ELF Format)Program Structure in GNU/Linux (ELF Format)
Program Structure in GNU/Linux (ELF Format)
Varun Mahajan
 

Was ist angesagt? (20)

web programming UNIT VIII python by Bhavsingh Maloth
web programming UNIT VIII python by Bhavsingh Malothweb programming UNIT VIII python by Bhavsingh Maloth
web programming UNIT VIII python by Bhavsingh Maloth
 
Dynamic Linker
Dynamic LinkerDynamic Linker
Dynamic Linker
 
java networking
 java networking java networking
java networking
 
working file handling in cpp overview
working file handling in cpp overviewworking file handling in cpp overview
working file handling in cpp overview
 
Network programming in java - PPT
Network programming in java - PPTNetwork programming in java - PPT
Network programming in java - PPT
 
Program Structure in GNU/Linux (ELF Format)
Program Structure in GNU/Linux (ELF Format)Program Structure in GNU/Linux (ELF Format)
Program Structure in GNU/Linux (ELF Format)
 
2CPP17 - File IO
2CPP17 - File IO2CPP17 - File IO
2CPP17 - File IO
 
08. handling file streams
08. handling file streams08. handling file streams
08. handling file streams
 
Filehandling
FilehandlingFilehandling
Filehandling
 
PE File Format
PE File FormatPE File Format
PE File Format
 
Exploitation Crash Course
Exploitation Crash CourseExploitation Crash Course
Exploitation Crash Course
 
Files and streams
Files and streamsFiles and streams
Files and streams
 
Filehandlinging cp2
Filehandlinging cp2Filehandlinging cp2
Filehandlinging cp2
 
Tcp/ip server sockets
Tcp/ip server socketsTcp/ip server sockets
Tcp/ip server sockets
 
web programming Unit VI PPT by Bhavsingh Maloth
web programming Unit VI PPT  by Bhavsingh Malothweb programming Unit VI PPT  by Bhavsingh Maloth
web programming Unit VI PPT by Bhavsingh Maloth
 
Unit VI
Unit VI Unit VI
Unit VI
 
17 files and streams
17 files and streams17 files and streams
17 files and streams
 
File Pointers
File PointersFile Pointers
File Pointers
 
Introduction to Dart
Introduction to DartIntroduction to Dart
Introduction to Dart
 
File handling in c++
File handling in c++File handling in c++
File handling in c++
 

Ähnlich wie Post exploitation techniques on OSX and Iphone, EuSecWest 2009

[Defcon24] Introduction to the Witchcraft Compiler Collection
[Defcon24] Introduction to the Witchcraft Compiler Collection[Defcon24] Introduction to the Witchcraft Compiler Collection
[Defcon24] Introduction to the Witchcraft Compiler Collection
Moabi.com
 
Hs P005 Reflective Dll Injection
Hs P005 Reflective Dll InjectionHs P005 Reflective Dll Injection
Hs P005 Reflective Dll Injection
KarlFrank99
 
Low Level Exploits
Low Level ExploitsLow Level Exploits
Low Level Exploits
hughpearse
 
Os Worthington
Os WorthingtonOs Worthington
Os Worthington
oscon2007
 
Man in-the-browser-in-depth-report
Man in-the-browser-in-depth-reportMan in-the-browser-in-depth-report
Man in-the-browser-in-depth-report
Hai Nguyen
 
Security Applications For Emulation
Security Applications For EmulationSecurity Applications For Emulation
Security Applications For Emulation
Silvio Cesare
 
Joxean Koret - Database Security Paradise [Rooted CON 2011]
Joxean Koret - Database Security Paradise [Rooted CON 2011]Joxean Koret - Database Security Paradise [Rooted CON 2011]
Joxean Koret - Database Security Paradise [Rooted CON 2011]
RootedCON
 
Os7 2
Os7 2Os7 2
Os7 2
issbp
 

Ähnlich wie Post exploitation techniques on OSX and Iphone, EuSecWest 2009 (20)

[Defcon24] Introduction to the Witchcraft Compiler Collection
[Defcon24] Introduction to the Witchcraft Compiler Collection[Defcon24] Introduction to the Witchcraft Compiler Collection
[Defcon24] Introduction to the Witchcraft Compiler Collection
 
Hs P005 Reflective Dll Injection
Hs P005 Reflective Dll InjectionHs P005 Reflective Dll Injection
Hs P005 Reflective Dll Injection
 
Low Level Exploits
Low Level ExploitsLow Level Exploits
Low Level Exploits
 
A Life of breakpoint
A Life of breakpointA Life of breakpoint
A Life of breakpoint
 
Let your Mach-O fly, Black Hat DC 2009
Let your Mach-O fly, Black Hat DC 2009Let your Mach-O fly, Black Hat DC 2009
Let your Mach-O fly, Black Hat DC 2009
 
Mach-O Internals
Mach-O InternalsMach-O Internals
Mach-O Internals
 
Failure Of DEP And ASLR
Failure Of DEP And ASLRFailure Of DEP And ASLR
Failure Of DEP And ASLR
 
Creating a Fibonacci Generator in Assembly - by Willem van Ketwich
Creating a Fibonacci Generator in Assembly - by Willem van KetwichCreating a Fibonacci Generator in Assembly - by Willem van Ketwich
Creating a Fibonacci Generator in Assembly - by Willem van Ketwich
 
Fun and Games with Mac OS X and iPhone Payloads White Paper, Black Hat EU 2009
Fun and Games with Mac OS X and iPhone Payloads White Paper, Black Hat EU 2009Fun and Games with Mac OS X and iPhone Payloads White Paper, Black Hat EU 2009
Fun and Games with Mac OS X and iPhone Payloads White Paper, Black Hat EU 2009
 
Os Worthington
Os WorthingtonOs Worthington
Os Worthington
 
Man in-the-browser-in-depth-report
Man in-the-browser-in-depth-reportMan in-the-browser-in-depth-report
Man in-the-browser-in-depth-report
 
Security Applications For Emulation
Security Applications For EmulationSecurity Applications For Emulation
Security Applications For Emulation
 
Joxean Koret - Database Security Paradise [Rooted CON 2011]
Joxean Koret - Database Security Paradise [Rooted CON 2011]Joxean Koret - Database Security Paradise [Rooted CON 2011]
Joxean Koret - Database Security Paradise [Rooted CON 2011]
 
Tranning-2
Tranning-2Tranning-2
Tranning-2
 
Malicious pdf Exploit Unravelled
Malicious pdf Exploit UnravelledMalicious pdf Exploit Unravelled
Malicious pdf Exploit Unravelled
 
Build your own discovery index of scholary e-resources
Build your own discovery index of scholary e-resourcesBuild your own discovery index of scholary e-resources
Build your own discovery index of scholary e-resources
 
Dive into exploit development
Dive into exploit developmentDive into exploit development
Dive into exploit development
 
College Project - Java Disassembler - Description
College Project - Java Disassembler - DescriptionCollege Project - Java Disassembler - Description
College Project - Java Disassembler - Description
 
Description of VivaVisualCode
Description of VivaVisualCodeDescription of VivaVisualCode
Description of VivaVisualCode
 
Os7 2
Os7 2Os7 2
Os7 2
 

Mehr von Vincenzo Iozzo (10)

A tale of mobile threats
A tale of mobile threatsA tale of mobile threats
A tale of mobile threats
 
Stale pointers are the new black
Stale pointers are the new blackStale pointers are the new black
Stale pointers are the new black
 
Stale pointers are the new black - white paper
Stale pointers are the new black - white paperStale pointers are the new black - white paper
Stale pointers are the new black - white paper
 
Everybody be cool, this is a ROPpery - White paper
Everybody be cool, this is a ROPpery - White paperEverybody be cool, this is a ROPpery - White paper
Everybody be cool, this is a ROPpery - White paper
 
Everybody be cool, this is a ROPpery
Everybody be cool, this is a ROPperyEverybody be cool, this is a ROPpery
Everybody be cool, this is a ROPpery
 
0-knowledge fuzzing white paper
0-knowledge fuzzing white paper0-knowledge fuzzing white paper
0-knowledge fuzzing white paper
 
0-knowledge fuzzing
0-knowledge fuzzing0-knowledge fuzzing
0-knowledge fuzzing
 
Let Your Mach-O Fly, Black Hat DC 2009
Let Your Mach-O Fly, Black Hat DC 2009Let Your Mach-O Fly, Black Hat DC 2009
Let Your Mach-O Fly, Black Hat DC 2009
 
Fun and Games with Mac OS X and iPhone Payloads, Black Hat Europe 2009
Fun and Games with Mac OS X and iPhone Payloads, Black Hat Europe 2009Fun and Games with Mac OS X and iPhone Payloads, Black Hat Europe 2009
Fun and Games with Mac OS X and iPhone Payloads, Black Hat Europe 2009
 
Post Exploitation Bliss: Loading Meterpreter on a Factory iPhone, Black Hat U...
Post Exploitation Bliss: Loading Meterpreter on a Factory iPhone, Black Hat U...Post Exploitation Bliss: Loading Meterpreter on a Factory iPhone, Black Hat U...
Post Exploitation Bliss: Loading Meterpreter on a Factory iPhone, Black Hat U...
 

Kürzlich hochgeladen

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Kürzlich hochgeladen (20)

The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 

Post exploitation techniques on OSX and Iphone, EuSecWest 2009

  • 1. Post exploitation techniques on OSX and Iphone VincenzoIozzo vincenzo.iozzo@zynamics.com
  • 2. Who I am Student at PolitecnicodiMilano Security Consultant at Secure Network srl Reverse Engineer at zynamics GmbH
  • 3. Quick overview The old guy: Userland-exec on OSX Some practical examples The new guy: Something similar to userland-exec on factory Iphone Proof that it works First step toward Meterpreter on factory iPhone
  • 4. Mach-O file Header structure: information on the target architecture and options to interpret the file. Load commands: symbol table location, registers state. Segments: define region of the virtual memory, contain sections with code or data.
  • 7. Let your Mach-O fly! Userland-exec Execute an application without the kernel Technique was presented at BH DC The first part of this talk covers technique and some applications of it to Mac OS X
  • 8. WWW Who: an attacker with a remote code execution in his pocket. Where: the attack is two-staged. First run a shellcode to receive the binary, then run the auto-loader contained in the binary. Why: later in this talk.
  • 9. What kind of binaries? Any Mach-O file, from ls to Safari In real life, probably stuff like keyboard sniffers, other not-so-nice programs
  • 10. What normally happens You want to run your binary: mybin execve system call is called Kernel parses the binary, maps code and data, and creates a stack for the binary Dyld resolves dependencies and jumps to the binary entry point
  • 11. What Mach-O on the Fly does Craft a binary which contains a stack identical to the one created by the kernel and a piece of code which mimics the kernel Send binary to exploited process Do some cleanup, jump to the dynamic linker entry point (as the kernel would do)
  • 13. Stack Mach-O file base address Command line arguments Environment variables Execution path All padded
  • 15. Auto-loader Embedded in binary Impersonates the kernel Un-maps the old binary Maps the new one
  • 16. Auto-loader description Parses the binary Reads the virtual addresses of the injected binary segments Unloads the attacked binary segments pointed by the virtual addresses Loads the injected binary segments
  • 17. Auto-loader description(2) Maps the crafted stack referenced by __PAGEZERO Cleans registers Cleans some libSystem variables Jumps to dynamic linker entry point
  • 18. We do like pictures, don’t we? Victim’s process address space TEXT DATA LINKEDIT SEGMENT -N TEXT DATA LINKEDIT SEGMENT-N
  • 19. Infected binary We need to find a place to store the auto-loader and the crafted stack __PAGEZERO infection technique Cavity infector technique
  • 20. PAGEZERO Infection Change __PAGEZERO protection flags with a custom value Store the crafted stack and the auto-loader code at the end of the binary Point __PAGEZERO to the crafted stack Overwrite the first bytes of the file with the auto-loader address
  • 21. Binary layout MODIFIED HEADER INFECTED __PAGEZERO LOAD COMMANDS AND SEGMENTS SECTIONS AND BINARY DATA SHELLCODE CRAFTED STACK
  • 22. Let’s clean things up We need to clean up some variables in order to make the attack work They are stored in libSystem They are not exported ASLR for libraries makes this non-trivial No dlopen/dlsym combo
  • 23. Defeat ASLR using the dynamic linker The dynamic linker has a list of the linked libraries We can access this list by using some of its function Remember that we want to perform everything in memory
  • 24. Useful dyld functions _dyld_image_count() used to retrieve the number of linked libraries of a process. _dyld_get_image_header() used to retrieve the base address of each library. _dyld_get_image_name() used to retrieve the name of a given library.
  • 25. Find ‘em Parse dyld load commands. Retrieve __LINKEDIT address. Iterate dyld symbol table and search for the functions name in __LINKEDIT.
  • 26. Back to libSystem Non-exported symbols are taken out from the symbol table when loaded. Open libSystem binary, find the variables in the symbol table. Adjust variables to the base address of the in-memory __DATA segment.
  • 27. Put pieces together Iterate the header structure of libSystem in-memory and find the __DATA base address. __DATA base address 0x2000 Symbol at 0x2054 In-memory __DATA base address 0x4000 Symbol in-memory at 0x4054
  • 28. Mach-O Fly payload Not much bigger than bind shellcode A lot of work is in preparing the binary to send
  • 29. Mach-O Fly payload(x86) char shellcode[] = "31c0504050405050b061cd809989c652” "525268000204d289e36a10535652b068” "cd80525652b06acd8052525652b01ecd” "8089c331c0504850b80210000050b807""00000050b9404b4c005131c05050b8c5” "000000cd8089c731c050506a40515753” "53b81d000000cd80578b078d0438ffe0"
  • 30. Results Execute a binary to an arbitrary machine. No traces on the hard-disk. No execve(), the kernel doesn’t know about us. It works with every binary. It is possible to write payloads in a high level language.
  • 31. DEMO
  • 33. Iphone nightmare - first step We (I and Charlie) tried to port my attack to Iphone and we succeeded on jailbroken ones We, as everyone else who tried to write attacks for this OS, were convinced it would have worked on factory phones too
  • 34. Iphone nightmare – step two It didn’t. Code signing and XN bit are a huge problem on factory iPhones You cannot execute a page unless is signed You cannot set a page executable if it was writable
  • 35. My face at this point
  • 36. A step toward success Just two days before our presentation at BH EU Charlie discovered that it is possible to set execution flags on a writable page But only shared libraries pages
  • 37. My face after Charlie’s discovery
  • 38. But still.. My attack could not work anyway cause we cannot touch the executable pages So instead of a binary we decided to inject a library.. .. It worked!
  • 39. My face at the end
  • 40. Why so? Until now there was no way to execute your own code on a factory phone No advanced payloads In most cases no payloads at all Just some very hard return-into-libSystem stuff With this attack we have: Advanced payloads(Meterpreter anyone?) No need to play with return-into-something stuff anymo
  • 41. A few questions How Charlie’s trick works? How can we map a library? Ok you have an injected library, now what? How do we play with dyld in order to link our library?
  • 42. How Charlie’s trick works? Three steps: Call vm_protect() in order to change page permissions to readable and writable Write whatever you want Call vm_protect() again with readable and executable flags
  • 43. How can we map a library? Mapping a library is no different from mapping an executable We need to make sure to map the injected library upon an already mapped one Clearly we cannot just memcpy() stuff
  • 44. Leveraging the trick For each segment we need to map we issue a vm_protect with READ and WRITE flags We copy the segment We issue another vm_protect with the protection flags the segment expects
  • 45. Ok you have an injected library, now what? A non-linked library is useless The linking process is in charge of resolving library dependencies and link the executable to the library We need to work on the dynamic linker in order to understand how to link it
  • 46. OsxdyldvsiPhonedyld On Osx you have a bunch of ways for linking a library stored in memory None of them work on iPhone (they have taken out the code for doing this)
  • 47. So how do you load a library on Iphone? The library must be on the disk You need to call dlopen() The library must be signed
  • 48. But our library is not signed, is it?
  • 49. What to do now? Dyld has still a way of mapping a binary from memory (it has to for loading the main binary) We should use it But it’s simply not enough
  • 50. The idea After we mapped the library we call dlopen() We hijack dlopen() execution in order to call the function which loads a binary from memory A few patches are needed
  • 53. So we’re done? Not really When the library is linked it searches for symbols in each linked library *each linked library* means even the one we have overwritten
  • 54. One last patch Before overwriting the victim library we force dlclose() to unlink it To “force” means to ignore the garbage collector for libraries We need to be careful with this one, some frameworks will crash if they are forced to be unloaded
  • 56. Results It is possible to load a arbitrary non-signed library in the address space of an arbitrary process (despite the code signing stuff) It’s the only reliable way to have a working-payloads on factory phones Rooms for improvements Meterpreter anyone?
  • 57. DEMO

Hinweis der Redaktion

  1. 30minuti