6 ms·
With BTI can the attacker not just write a BTI opcode to the start of the jump location? Usually you would jump to a buffer that you control the contents of (i.
by libeclipse 7y ago
With BTI can the attacker not just write a BTI opcode to the start of the jump location? Usually you would jump to a buffer that you control the contents of (i.e. shellcode)
- pcwalton 7y agoW^X prevents that straightforward attack, by not allowing writable buffers to be executed. The typical way to defeat W^X is ROP chains with gadgets consisting of pieces of code already present in the binary. BTI, in turn, is a defense against that. It's very much a cat and mouse game.
- monocasa 7y agoSo now we're going to see the next step be making gadgets out of code fragments that happen to begin with BTI. The real end game here is memory safety.
- armitron 7y agoNo real end game I'm afraid. Data-only attacks do exist (and are bound to become a lot more common).
- monocasa 7y agoEnd game for the class of remote code execution vulnerabilities.
- saagarjha 7y agoThat's where pointer authentication can help.
- wahern 7y agoThere are ways to compile that elide ROP gadgets. It's easier on architectures like ARM than x86. OpenBSD has taken this approach: Number of ROP gadgets in 6.3-release arm64 kernel 69935 Number of ROP gadgets in 6.4-beta arm64 kernel 46 https://www.openbsd.org/papers/eurobsdcon2018-rop.pdf https://www.openbsd.org/papers/eurobsdcon2018-rop.pdf Note: As described later in the presentation, those 46 remaining gadgets are in the boot code, which is erased after booting.
- monocasa 7y agoI'm not convinced that a conditional branch to the ret followed by breakpoints between it and the ret is enough to remove the usefulness of the gadget as much as they say.
- saagarjha 7y agoWhy?
- monocasa 7y agoIt's exactly the kind of roadblock that people who do offensive security are great at finding loopholes around.
- saagarjha 7y agoI mean, that's really been their job every time a new mitigation is developed…the introduction of NX led to the use of ROP, which has been joined by JOP techniques as efforts to remove return gadgets gain momentum.
- monocasa 7y agoThis is more like fitting shellcode into something that can be strcpyed. Not really that much of a complication from an attack perspective.
- saagarjha 7y agoI’m not convinced their search for ROP gadgets in libc is useful; often there’s a “magic” address that will do all the work to directly execve /bin/sh if you jump there (in glibc, this is inside of do_system).
- qubex 7y ago> memory safety Harvard Architecture?
- monocasa 7y agoOr a language that doesn't let you overflow buffers.
- armitron 7y agoThat hasn't been true in a very long time.