
Android Blueborne RCE CVE-2017-0781
Android Blueborne RCE CVE-2017-0781
2017년 11월, Armis라는 회사는 BlueBorne으로 알려진 Android의 Bluetooth를 통한 원격 코드 실행 취약점(CVE-2017-0781)에 대한 개념 증명(PoC)을 공개했습니다. BlueBorne은 8가지 취약점의 집합을 가리키지만, 이 문서의 PoC는 그중 2가지만 사용하여 목표를 달성합니다.
BlueBorne은 장치에서 Bluetooth 연결이 활성화되어 있기만 하면 됩니다. 사용자 작업이 필요 없으며, 기기가 페어링되어 있을 필요도 없습니다. 해커는 여러분의 기기와 Bluetooth 범위 안에 있기만 하면 그 기기를 장악할 수 있습니다.
공격 과정은 2단계로 나뉩니다. 먼저 메모리 누수 취약점(CVE-2017-0785)을 사용하여 메모리 주소를 알아내고 ASLR 보호를 우회한 다음, libc 라이브러리의 system 함수를 호출하여 휴대폰에서 코드를 실행하고 파일("/data/local/tmp/test")을 생성합니다. 원하는 페이로드로 변경할 수 있으며, 모바일이 여러분에게 연결되도록 하는 것(리버스 셸)도 포함됩니다.
이 문서에서는 BlueBorne 패치가 적용되지 않았거나 Android 2017년 9월 보안 패치가 적용되지 않은 영향을 받는 휴대폰에서 코드를 실행하고/하거나 장악할 수 있음을 보여드리고자 합니다.
관심이 있다면 아래에 디버거 로그와 실행 로그, 그리고 페이로드 실행 증거가 있습니다.
테스트 목적으로 CVE-2017-0781 패치를 제거하고 테스트용 모바일 Samsung S3 Neo+ GT-9301I에 Android 7.1.2(LineageOS CM 14.1)를 컴파일했습니다.
자세한 정보는 여기:
https://github.com/marcinguy/S3NEO--GT301I
수십 번의 실행 후에 이러한 상태가 발생했습니다. 각 실행은 약 2~3초 정도 걸립니다. 따라서 1분의 절반도 안 되는 시간 안에 모바일을 장악/탈취할 수 있습니다.```asm License GPLv3+: GNU GPL version 3 or later http://gnu.org/licenses/gpl.html This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Type "show copying" and "show warranty" for details. This GDB was configured as "arm-linux-androideabi". Type "show configuration" for configuration details. For bug reporting instructions, please see: http://www.gnu.org/software/gdb/bugs/. Find the GDB manual and other documentation resources online at: http://www.gnu.org/software/gdb/documentation/. For help, type "help". Type "apropos word" to search for commands related to "word". (gdb) attach 15513 Attaching to process 15513 [New LWP 15518] [New LWP 15519] [New LWP 15520] [New LWP 15521] [New LWP 15522] [New LWP 15523] [New LWP 15524] [New LWP 15525] [New LWP 15526] [New LWP 15529] [New LWP 15530] [New LWP 15531] [New LWP 15532] [New LWP 15533] [New LWP 15534] [New LWP 15535] [New LWP 15536] [New LWP 15537] [New LWP 15538] [New LWP 15539] [New LWP 15541] [New LWP 15540] [New LWP 15543] [New LWP 15544] [New LWP 15545] [New LWP 15546] [New LWP 15547] [New LWP 15548] [New LWP 15549] [New LWP 15550] [New LWP 15551] [New LWP 15552] [New LWP 15556] [New LWP 15557] [New LWP 15558] [New LWP 15559] [New LWP 15560] [New LWP 15562] [New LWP 15563] [New LWP 15565] [New LWP 15569] [New LWP 15570] [New LWP 15577] [New LWP 15578] 0xb5219114 in __epoll_pwait () from target:/system/lib/libc.so (gdb) b *0xb5216b4d warning: Breakpoint address adjusted from 0xb5216b4d to 0xb5216b4c. Breakpoint 1 at 0xb5216b4c (gdb) disass system Dump of assembler code for function system: 0xb5216b4c <+0>: push {r4, r5, r6, lr} 0xb5216b4e <+2>: sub sp, #72 ; 0x48 0xb5216b50 <+4>: ldr r1, [pc, #236] ; (0xb5216c40 <system+244>) 0xb5216b52 <+6>: cmp r0, #0 0xb5216b54 <+8>: ldr r2, [pc, #236] ; (0xb5216c44 <system+248>) 0xb5216b56 <+10>: add r1, pc 0xb5216b58 <+12>: ldr r1, [r1, #0] 0xb5216b5a <+14>: add r2, pc 0xb5216b5c <+16>: vld1.64 {d16-d17}, [r2] 0xb5216b60 <+20>: ldr r1, [r1, #0] 0xb5216b62 <+22>: str r1, [sp, #68] ; 0x44 0xb5216b64 <+24>: add r1, sp, #48 ; 0x30 0xb5216b66 <+26>: vst1.64 {d16-d17}, [r1] 0xb5216b6a <+30>: beq.n 0xb5216bf6 <system+170> 0xb5216b6c <+32>: add r4, sp, #12 0xb5216b6e <+34>: str r0, [sp, #56] ; 0x38 0xb5216b70 <+36>: mov r0, r4 0xb5216b72 <+38>: blx 0xb51e4a38 sigemptyset@plt 0xb5216b76 <+42>: mov r0, r4 0xb5216b78 <+44>: movs r1, #17 0xb5216b7a <+46>: blx 0xb51e511c sigaddset@plt 0xb5216b7e <+50>: add r2, sp, #8 ---Type to continue, or q to quit---q Quit (gdb) cont Continuing. [New LWP 15912] [Switching to LWP 15540] warning: Breakpoint 1 address previously adjusted from 0xb5216b4d to 0xb5216b4c.