Saltar al contenido

0x8000 · Área

Explotación ARM64

El teléfono en tu bolsillo, la mayoría de los portátiles modernos y una parte creciente de los servidores usan AArch64, cuyo modelo de explotación difiere de x86-64 en aspectos importantes: la dirección de retorno vive en un registro, no en la pila por defecto, y la arquitectura incorpora defensas de hardware — autenticación de punteros e identificación de destinos de salto — que atacan directamente la reutilización de código. Esta área reconstruye en ARM las técnicas de las guías x86-64, en laboratorio, y explica cómo PAC y BTI cambian el juego.

Guías de esta área

  1. On AArch64 the return address lives in a register, not on the stack — until a non-leaf function saves it. Build the ARM ret2win in a lab and see where the saved link register sits.

  2. AArch64 gadgets end in ret, which branches to x30 — so the chain is threaded through the link register with ldp gadgets. Build a system("/bin/sh") chain, then watch PAC and BTI break it.

  3. Pointer authentication signs return addresses so a forged one faults; BTI forces indirect branches onto landing pads. How both work, how to enable and verify them, and their limits.

Las guías se publican primero en inglés. Las traducciones llegarán después.

Otras áreas