
Android Blueborne RCE CVE-2017-0781
2017年11月,一家名为Armis的公司发布了一个概念验证(PoC),展示了通过蓝牙在Android上实现远程代码执行的漏洞(CVE-2017-0781),称为BlueBorne。尽管BlueBorne指的是一组8个漏洞,但本文中的PoC仅使用了其中的2个来实现目标。
BlueBorne仅要求设备的蓝牙连接处于活动状态。不需要用户操作,甚至不需要设备配对。黑客只需要在设备的蓝牙范围内即可接管设备。
利用过程分为两个阶段:首先使用内存泄漏漏洞(CVE-2017-0785)来获取内存地址并绕过ASLR保护,从而调用libc库的system函数,在手机上执行代码,创建一个文件("/data/local/tmp/test")。你可以根据需要更改payload,包括让手机连接到你的设备(反向shell)。
在本文中,我想展示在受影响的手机上(即未安装BlueBorne补丁、未安装Android 2017年9月安全补丁的手机)执行代码和/或接管手机是可能的。
如果你感兴趣,下面是调试器日志和执行日志,以及payload执行的证明。
为测试目的,我在我的测试手机Samsung S3 Neo+ GT-9301I上移除了CVE-2017-0781补丁,并编译了Android 7.1.2(LineageOS CM 14.1)。
更多信息见:
https://github.com/marcinguy/S3NEO--GT301I
经过数十次执行后,我达到了这个条件。每次执行大约需要2-3秒。因此,你可以在不到半分钟的时间内拥有/接管手机。```asm License GPLv3+: GNU GPL version 3 or later http://gnu.org/licenses/gpl.html This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Type "show copying" and "show warranty" for details. This GDB was configured as "arm-linux-androideabi". Type "show configuration" for configuration details. For bug reporting instructions, please see: http://www.gnu.org/software/gdb/bugs/. Find the GDB manual and other documentation resources online at: http://www.gnu.org/software/gdb/documentation/. For help, type "help". Type "apropos word" to search for commands related to "word". (gdb) attach 15513 Attaching to process 15513 [New LWP 15518] [New LWP 15519] [New LWP 15520] [New LWP 15521] [New LWP 15522] [New LWP 15523] [New LWP 15524] [New LWP 15525] [New LWP 15526] [New LWP 15529] [New LWP 15530] [New LWP 15531] [New LWP 15532] [New LWP 15533] [New LWP 15534] [New LWP 15535] [New LWP 15536] [New LWP 15537] [New LWP 15538] [New LWP 15539] [New LWP 15541] [New LWP 15540] [New LWP 15543] [New LWP 15544] [New LWP 15545] [New LWP 15546] [New LWP 15547] [New LWP 15548] [New LWP 15549] [New LWP 15550] [New LWP 15551] [New LWP 15552] [New LWP 15556] [New LWP 15557] [New LWP 15558] [New LWP 15559] [New LWP 15560] [New LWP 15562] [New LWP 15563] [New LWP 15565] [New LWP 15569] [New LWP 15570] [New LWP 15577] [New LWP 15578] 0xb5219114 in __epoll_pwait () from target:/system/lib/libc.so (gdb) b *0xb5216b4d warning: Breakpoint address adjusted from 0xb5216b4d to 0xb5216b4c. Breakpoint 1 at 0xb5216b4c (gdb) disass system Dump of assembler code for function system: 0xb5216b4c <+0>: push {r4, r5, r6, lr} 0xb5216b4e <+2>: sub sp, #72 ; 0x48 0xb5216b50 <+4>: ldr r1, [pc, #236] ; (0xb5216c40 <system+244>) 0xb5216b52 <+6>: cmp r0, #0 0xb5216b54 <+8>: ldr r2, [pc, #236] ; (0xb5216c44 <system+248>) 0xb5216b56 <+10>: add r1, pc 0xb5216b58 <+12>: ldr r1, [r1, #0] 0xb5216b5a <+14>: add r2, pc 0xb5216b5c <+16>: vld1.64 {d16-d17}, [r2] 0xb5216b60 <+20>: ldr r1, [r1, #0] 0xb5216b62 <+22>: str r1, [sp, #68] ; 0x44 0xb5216b64 <+24>: add r1, sp, #48 ; 0x30 0xb5216b66 <+26>: vst1.64 {d16-d17}, [r1] 0xb5216b6a <+30>: beq.n 0xb5216bf6 <system+170> 0xb5216b6c <+32>: add r4, sp, #12 0xb5216b6e <+34>: str r0, [sp, #56] ; 0x38 0xb5216b70 <+36>: mov r0, r4 0xb5216b72 <+38>: blx 0xb51e4a38 sigemptyset@plt 0xb5216b76 <+42>: mov r0, r4 0xb5216b78 <+44>: movs r1, #17 0xb5216b7a <+46>: blx 0xb51e511c sigaddset@plt 0xb5216b7e <+50>: add r2, sp, #8 ---Type to continue, or q to quit---q Quit (gdb) cont Continuing. [New LWP 15912] [Switching to LWP 15540] warning: Breakpoint 1 address previously adjusted from 0xb5216b4d to 0xb5216b4c.