3 ms·
To take a very simple example (which won't work on modern OS with ASLR): 1. You have a service that takes some user input 2. The service allocates a buffer on
by thinkharderdev 3y ago
To take a very simple example (which won't work on modern OS with ASLR):
1. You have a service that takes some user input
2. The service allocates a buffer on the stack for 20 bytes (the max input allowed)
3. Service doesn't actually validate that the user input is < 20 bytes
4. It writes the input into the buffer, but keeps writing past the end of the buffer.
5. It eventually overwrites the return pointer so now the user input can control where the execution jumps to on return
6. In the user input, the malicious user includes some shell code to do any arbitrary thing they want.
7. The overwrite the return pointer to jump back into the shell code and now they are executing arbitrary code in the server process.
This sort of thing was embarrassingly easy to do on old linux kernels before ASLR was implemented. Now it is dramatically harder because there are all sorts of countermeasures in place to prevent it (ASLR, stack canaries, executable vs non-executable memory, etc).
To get a sense of what a more modern real world exploit looks like, give https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i... a read.
- pier25 3y agoThanks for the detailed response!