Zum Inhalt springen

0x7000 · Bereich

Exploit-Techniken

Ein Bug ist erst dann eine Schwachstelle, wenn jemand ihn in Kontrolle über ein Programm verwandelt. Dieser Bereich geht die klassischen Techniken dafür von Anfang bis Ende durch — eine gespeicherte Rücksprungadresse kapern, vorhandenen Code per ROP verketten, in libc zurückrufen, die GOT überschreiben — an kleinen, absichtlich verwundbaren Programmen, die Sie selbst mit abgeschalteten Mitigationen in einem Wegwerf-Labor kompilieren. Jede Anleitung schließt damit, die Mitigation wieder zu aktivieren, die sie bricht, sodass der offensive Schritt und die Abwehr, die ihn stoppt, nebeneinander stehen. So lernen Verteidiger, wogegen sie sich verteidigen.

Leitfäden in diesem Bereich

  1. A complete lab walkthrough: build a vulnerable C program, find the offset to the saved return address, redirect execution with pwntools, then watch each mitigation break the exploit.

  2. With NX on, injected shellcode is dead — so we reuse the program's own code. A full lab walkthrough: find gadgets, hand-build an execve syscall chain with pwntools, then watch CET and CFI break it.

  3. NX is on and the binary is tiny, but libc is mapped and full of useful code. Leak its base past ASLR, then return straight into system("/bin/sh") — a full two-stage pwntools walkthrough.

  4. One printf(user_input) is a full read/write primitive. Leak with %p, overwrite with %n via pwntools, then watch -Wformat=2 and FORTIFY_SOURCE shut it down.

  5. Lazy binding leaves the Global Offset Table writable. Aim an arbitrary write at a GOT entry, turn puts() into system(), then enable Full RELRO and watch the same write fault instantly.

  6. The heap's own metadata is the write primitive. Build a use-after-free, poison the glibc tcache to allocate a chunk over a chosen address, and see why safe-linking and ASan raise the bar.

  7. Modern exploits are leak-then-act. Build an out-of-bounds read, then use it to recover a stack canary, the PIE base and the libc base — the three secrets every mitigation relies on.

  8. When gadgets are scarce, forge a signal frame. A sigreturn syscall restores every register from the stack at once — build one with pwntools to call execve, then see how seccomp and CET respond.

  9. No pop rdx gadget? The C runtime's startup code has a universal sequence that loads several registers and makes a controlled call. Build it with pwntools, and see where it's gone.

  10. When the overflow gives you only a few bytes past the return address, pivot the stack pointer into a buffer you fully control and run the real chain from there. A pwntools walkthrough.

  11. When hooks are gone, the FILE object is the target. A stdio call dispatches through a vtable pointer in writable memory — corrupt it and the next fwrite runs your code.

  12. No libc leak, no problem: forge the relocation the dynamic linker reads and make it resolve and call system for you. A pwntools walkthrough — and why Full RELRO ends it.

  13. Sometimes you control just one pointer. A one-gadget is a single libc address that calls execve("/bin/sh") — if its register and stack constraints hold. Find one, check the constraints, and use it.

  14. A seccomp policy that bans execve takes the shell off the table, so attackers switch goals: open the flag, read it, write it back. Build the ORW chain, and see what a tighter policy stops.

Leitfäden erscheinen zuerst auf Englisch. Übersetzungen folgen.

Weitere Bereiche