Let's begin..
In this practice I use the BigAnt server application. BigAnt server is a server messaging application. This software built using SEH and linker SEH, that makes these applications is not easy to be exploited using direct RETN EIP like in case of WarFTP.
- Now, we will create a fuzzer to make an application error.
- After we create a fuzzer, now run the BigAnt server, and attach to OllyDbg. Be careful when attach the process, because there is 3 running process on BigAnt server, in this practice I try to attach AntServer that running on port 6660. Run the BigAnt server on OllyDbg.
- If the BigAnt server already running on OllyDbg, then run the fuzzer and look at the register log of Ollydbg.
- After the fuzzer run, the application crashes. But now the EIP register not overwritten by buffer of fuzzer.
Why this happen? Because the application using SEH that will catch the exception that happen to application. To look into SEH, select View -> SEH Chain. You will see the dialog box of SEH Chain like below.
- The buffer that send saved in SEH Chain. To pass the exception program from SEH Chain to memory, press shift+F9 key. See what happen! The EIP change to 414141
- In the bottom right of the OllyDbg windows, we can see that the fuzzer's data sent to the application also entered the stack memory. To see it right click on the stack line then click follow in dump.
And then, on the Window Memory dump OllyDbg will see the buffer in the memory like below.
- There are several ways to overcome with SEH protection, and the most popular is POP, POP, RETN method. But to protect from exploitation, Windows has other exception handler called safeSEH. Beside safeSEH, Windows also other protection, it is IMAGE_DLLCHARACHTERISTICS_NO_SEH.
There are 2 things to consider when overwrite the SEH address:
1. The module not compiled with safeSEH On.
2. The module didn't have or using flag IMAGE_DLLCHARACHTERISTICS_NO_SEH option.
- BigAnt server did'nt have dll module file inside the folder application, so the next step is to find the dll that not standard installed in Windows system.
- In this case we will use vbajet32.dll to overwrite SEH address. That located C:\Windows\system32\vbajet32.dll. To access this module just click View -> Executable modules.
- Then search the command POP, POP, RETN inside this module. After we located in Executables modules, double click on the vbajet32.dll file. After getting into window CPU of vbajet32.dll, then right click Search For -> Sequence of Commands
- Instert POP r32, POP r32, and RETN like below.
- And then OllyDbg will direct to memory address that have vbajet32.dll inside it.
- Okey, next we will try to find where byte the SEH overwriten. Like before, in here we use pattern_create to make string pattern that use to be buffer on the fuzzer.
Spoiler:
- Note the value on the EIP register and check using pattern_offset.
- From the result we know that need 966 byte to trigger SEH handler. So, we must modify the fuzzer, change the value buffer to 966 byte.
- Re run the OllyDbg and BigAnt server. Attach the AntServer process and run the BigAnt from OllyDbg. Then run the fuzzer.
The application crash, and when we open the SEH Chain, we will see that the value buffer x41 succes successful entry into the SEH handler.
- Next, we will insert the offset address of vbajet32.dll that have POP, POP, RETN command into fuzzer. Dont forget to using little-endian format.
- Like alwasy, Re run the OllyDbg and BigAnt, attach the AntServer process, and run the BigAnt from OlluDbg. Before we run the fuzzer we set breakpoint on the memory address 0F9A196A to confirm is the exploit that made realy direct to the correct memory.
- Run the fuzzer and see what happen. The application crash, and when we open the SEH Chain, we get the result that process break when access to memory address 0F9A196A.
- Press shift+F9 to process into vbajet32.dll memory, then press shift+F9 again to process it into POP POP RETN command that located inside vbajet32.dll,and then press F7 until reach RETN command.
- There problem is space memory that available is just 4 byte. So, needed the other process to transfer to the location that has more space allocation. Rigth click on the first memory address xCC (012CFD7D) -> Follow in Dump -> Selection.
- When we see the result, we found there is still large free memory space (x90). That empty memory space can be used to set the shellcode.
- To process CPU to the empty space that contain a command to overwrite the SEH address we use command JMP SHORT. The JMP SHORT used to send a command for CPU to jump to next memory byte according to command that user want.
- Okey, next we will create a payload using msfweb.
Insert the restricted characters. There is an additional restricted characters, 0x20 and 0x25. This case will discussed in other post. After insert the restricted characters then generate the payload.
- Insert the result to the fuzzer.
- Run the BigAnt server without OllyDbg then run the fuzzer.
- Run telnet command to the target.
- Sucess!!
0 comments:
Post a Comment
Comment in here...