
CVE-2022-3786 (openssl) को Mayhem के साथ खोजना
इस रिपॉजिटरी में एक सहयोगी ब्लॉग पोस्ट है जिसका शीर्षक है "Finding CVE-2022-3786 (openssl) with Mayhem" जो https://www.seandeaton.com पर उपलब्ध है।
यह सब आपके लिए शामिल Dockerfile (साथ ही DockerHub पर भी) के साथ ध्यान रखा गया है। आप इसे इस प्रकार चला सकते हैं:
# Build the container
docker build --tag openssl-cve-2022-3768 .
# Or if you just want to pull down the existing one:
TODO
# Ensure that you're in this project's root directory (ie you can see ./output/)
# Mount the ./input/ directory to the containers /input. This is for fuzz input.
# This is Linux specific, Windows I think has %CD% in lieu of $(pwd)?
docker run --interactive --tty --volume $(pwd)/input:/input
कंटेनर का एंट्रीपॉइंट केवल afl चलाना है ताकि आप तुरंत फ़ज़िंग शुरू कर सकें। इस व्यवहार को ओवरराइड करने के लिए, docker run लाइन के अंत में /bin/bash जोड़ें।
अंतिम कमिट जिसमें यह कमजोरी शामिल है, वह 1 नवंबर 2022 का कमिट SHA 3b421ebc64c7b52f1b9feb3812bdc7781c784332 है। इसे कमिट SHA 680e65b94c916af259bfdc2e25f1ab6e0c7a97d6 में ठीक किया गया था। हम git के साथ आसानी से असुरक्षित संस्करण प्राप्त कर सकते हैं:
# Clone the repository.
git clone git://git.openssl.org/openssl.git
# Change into the working directory.
cd openssl
# Detach HEAD from origin to examine the code as it was when it was vulnerable.
git checkout 3b421ebc64c7b52f1b9feb3812bdc7781c784332
संकलन के लिए, हम AFL के gcc कंपाइलर का उपयोग करते हैं (क्योंकि clang के साथ मुझे लगातार अपरिभाषित संदर्भ मिल रहे थे)। छोटे बफर ओवरफ्लो ऑफसेट के कारण, हम एड्रेस सैनिटाइज़ेशन (ASAN) का भी उपयोग करना चाहते हैं, जो AFL के पर्यावरण चर AFL_USE_ASAN से सक्षम होता है। ASAN द्वारा बड़ी मात्रा में मेमोरी के उपयोग को देखते हुए, हमें एड्रेस स्पेस को प्रतिबंधित करने की भी आवश्यकता है, जो हम प्रोग्राम को 32-बिट आर्किटेक्चर के लिए संकलित करके कर सकते हैं। अधिक जानकारी यहाँ।
OpenSSL का 32-बिट के लिए कॉन्फ़िगरेशन फ़्लैग -m32 और linux-generic32 लेता है। compile.sh स्क्रिप्ट यह आपके लिए करती है।
# Configuration
AFL_USE_ASAN=1 CC=afl-gcc-fast CXX=afl-g++-fast ./Configure -m32 linux-generic32
# Make
AFL_USE_ASAN=1 CC=afl-gcc-fast CXX=afl-g++-fast CFLAGS="-m32" CXXFLAGS="-m32" make
यह आपके सिस्टम के संसाधनों के आधार पर कुछ समय ले सकता है। संकलन के बाद, हमें अपना हार्नेस संकलित करना होगा। एक Makefile दिया गया है।
# Compile the harness.
$ make harness
# Run the harness.
$ ./harness input/seed0.txt
ossl_a2ulabel returned: 1
और देखिए, आप openssl में ossl_a2ulabel का फ़ज़िंग शुरू कर सकते हैं। AFL के साथ कमांड कुछ इस प्रकार दिखता है (या शामिल run.sh स्क्रिप्ट का उपयोग करें)।
afl-fuzz -i /input -o /output /harness/harness @@