5 ms·
They are injecting code into running Finder process? Hmmm, so they figured one of the jump instructions target address in Finder process ( for a function invoca
by simplekoala 15y ago
They are injecting code into running Finder process? Hmmm, so they figured one of the jump instructions target address in Finder process ( for a function invocation, most likely the code to show the pop-up), and changed that location to jump to a different address where they injected their code? Don't you need root privileges to muck with Finder's process space? I see dropbox process running with non-privileged uid. Wonder, how they managed to change the VMM space of Finder process to inject code. Any thoughts? Please correct me, if I am totally off the mark here.
- JonnieCache 15y agoI think there are some hooks in OSX/Cocoa for doing this, although I don't claim to actually understand it. There is the SIMBL system which people used to write native plugins for Safari, I guess that's probably stopped since it has an actual extension framework now. http://www.culater.net/software/SIMBL/SIMBL.php http://www.culater.net/software/SIMBL/SIMBL.php Then there's TotalFinder, which uses in-memory patching to add tabs and all sorts of other leet stuff into Finder. I highly recommend it. In their docs they say it works similarly to SIMBL. http://totalfinder.binaryage.com/ http://totalfinder.binaryage.com/
- scott_s 15y agoSo, hijacking shared libraries. I doubt they're actually changing the Finder process in memory. I bet their changes are localized to the library they hijack.
- simplekoala 15y agoThanks for the info. On further digging, I found this useful link - http://www.culater.net/wiki/moin.cgi/CocoaReverseEngineering http://www.culater.net/wiki/moin.cgi/CocoaReverseEngineering which provides some insights into accomplishing what Dropbox did.
- scott_s 15y agoA process can't change the address space of another process, period. Even if one is a root process. Separation of address spaces is a basic security service provided by the operating system. So I'm also puzzled how they are able to modify memory in Finder's address space. The closest thing I can think of is that Finder executes arbitrary processes on behalf of the user. That is, when I double click on something, Finder has to do the fork-exec dance to launch that application. A process fork, however, creates an entirely separate address space for the new process. I would be shocked if Finder did not do that. So, yes, I'm also wondering what it is they do.
- simplekoala 15y agoThanks for the clarification. I was thinking may be they were mucking with shared libraries. I found this useful link on digging further. Doesn't seem like too much of black art. http://www.culater.net/wiki/moin.cgi/CocoaReverseEngineering http://www.culater.net/wiki/moin.cgi/CocoaReverseEngineering
- tlrobinson 15y agoNot true, at least on OS X: http://www.slideshare.net/rentzsch/dynamic-overriding http://www.slideshare.net/rentzsch/dynamic-overriding https://github.com/rentzsch/mach_star https://github.com/rentzsch/mach_star I don't know if this is how Dropbox works, but it seems likely.
- scott_s 15y agoThe first chunk of those slides talk about library hijacking. Say, you define your own version of malloc, make sure the application links to your version of malloc, and play your tricks from there. Process isolation has not been violated. The last five slides seem to be doing this: http://www.blackhat.com/presentations/bh-usa-09/DAIZOVI/BHUSA09-Daizovi-AdvOSXRootkits-SLIDES.pdf http://www.blackhat.com/presentations/bh-usa-09/DAIZOVI/BHUS... Slide 4 is the difference: OSX is BSD running on top of Mach. So these techniques use the Mach layer to get around basic process protection. This is terribly insecure.
- tlrobinson 15y agoYeah, the injection stuff was what I was referring to. Apple apparently changed OS X in 10.4.4 to only allow root or procmod group to do this http://guiheneuf.org/mach%20inject%20for%20intel.html http://guiheneuf.org/mach%20inject%20for%20intel.html
- ataranto 15y agoDropbox does in fact use mach_star.
- wmf 15y ago