1 / 6100%
rz-bin -I test | grep 'size:' | awk '{print $2}'
GEF(pronounced ʤɛf - "Jeff") is a set of commands for x86/64, ARM, MIPS,
PowerPC and SPARC to assist exploit developers and reverse-engineers when
using old school GDB. It provides additional features to GDB using the Python
API to assist during the process of dynamic analysis and exploit
development. Application developers will also benefit from it, as GEF lifts a
great part of regular GDB obscurity, avoiding repeating traditional
commands, or bringing out the relevant information from the debugging
runtime.
Simply make sure you haveGDB 10.0 or highercompiled
with Python3.10+ bindings, then:
# via the install script
## using curl
$ bash -c "$(curl -fsSL https://gef.blah.cat/sh)"
## using wget
$ bash -c "$(wget https://gef.blah.cat/sh -O -)"
# or manually
$ wget -O ~/.gdbinit-gef.py -q https://gef.blah.cat/py
$ echo source ~/.gdbinit-gef.py >> ~/.gdbinit
# or alternatively from inside gdb directly
$ gdb -q
(gdb) pi import urllib.request as u, tempfile as t;
g=t.NamedTemporaryFile(suffix='-gef.py'); open(g.name,
'wb+').write(u.urlopen('https://tinyurl.com/gef-main').read());
gdb.execute('source %s' % g.name)
Excellent! Now it's time to talk about Buffer Overflows.
◉
◉ ◉
◉ Buffer Overflow means there is a buffer of characters, integers or any
other type of variables, ◉
◉ and someone inserts into this buffer more bytes than it can store.
◉
◉ ◉
◉ If the user inserts more bytes than the buffer's size, they will be stored
somewhere in the memory ◉
◉ after the address of the buffer, overwriting important addresses for the
flow of the program. ◉
◉ This, in most cases, will make the program crash.
◉
◉ ◉
◉ When a function is called, the program knows where to return because of
the 'return address'. If the ◉
◉ player overwrites this address, they can redirect the flow of the program
wherever they want. ◉
◉ To print a function's address, run 'p <function_name>' inside 'gdb'. (e.g. p
main) ◉
◉ ◉
◉ gef➤ p gg ◉
◉ $1 = {<text variable, no debug info>} 0x401176 <gg>
◉
◉ ◉
◉ To perform a Buffer Overflow in the simplest way, we take these things
into consideration. ◉
◉ ◉
◉ 1. Canary is disabled so it won't quit after the canary address is
overwritten. ◉
◉ 2. PIE is disabled so the addresses of the binary functions are not
randomized and the user knows ◉
◉ where to return after overwritting the return address.
◉
◉ 3. There is a buffer with N size.
◉
◉ 4. There is a function that reads to this buffer more than N bytes.
◉
◉ ◉
◉ Run printf 'A%.0s' {1..30} | ./test to enter 30*"A" into the program.
◉
◉ ◉
◉ Run the program manually with "./test" and insert 30*A, then 39, then 40
and see what happens. ◉
gdb -q vault
Reading symbols from vault...
(No debugging symbols found in vault)
gef➤ break *(0x555555554000 + 0xc3a1)
Breakpoint 1 at 0x5555555603a1
gef➤ run
Starting program: ./vault
Breakpoint 1, 0x00005555555603a1 in ?? ()
gef➤ x/i $rip
=> 0x5555555603a1: cmp eax,ecx
gef➤ p/c $rax
$1 = 0x48
gef➤ p/c $rcx
$2 = 0x48
gef➤ set $rax = $rcx
gef➤ continue
Continuing.
Breakpoint 1, 0x00005555555603a1 in ?? ()
$ gdb -q rebuilding
Reading symbols from rebuilding...
(No debugging symbols found in rebuilding)
gef➤ disassemble main
Dump of assembler code for function main:
gef➤ break *main+303
Breakpoint 1 at 0x9b6
gef➤ run $(python3 -c 'print("A" * 32)')
Starting program: ./rebuilding $(python3 -c 'print("A" * 32)')
Preparing secret keys
Calculating.
Breakpoint 1, 0x00005555554009b6 in main ()
gef➤ x/i $rip
=> 0x5555554009b6 <main+303>: cmp cl,al
gef➤ p/c $rcx
$1 = 0x48
gef➤ p/c $rax
$2 = 0x41
So the expected value for:$rax:is:0x48:(H). Let’s change it and continue:
gef➤ set $rax = $rcx
gef➤ continue
Continuing.
Calculating .
Breakpoint 1, 0x00005555554009b6 in main ()
gef➤ p/c $rcx
$3 = 0x54
gef➤ disassemble main
Dump of assembler code for function main:
...
0x000055555540098e <+263>: movsxd rdx,edx
0x0000555555400991 <+266>: lea rax,[rip+0x2006aa] #
0x555555601042 <key>
0x0000555555400998 <+273>: movzx eax,BYTE PTR [rdx+rax*1]
0x000055555540099c <+277>: xor esi,eax
...
gef➤ x/s 0x555555601042
Students also viewed