WWW2Exec - __malloc_hook & __free_hook
Last updated
Last updated
AWSăăăăłă°ăćŠăłăćźè·”ăă:HackTricks Training AWS Red Team Expert (ARTE) GCPăăăăłă°ăćŠăłăćźè·”ăă: HackTricks Training GCP Red Team Expert (GRTE)
ć
ŹćŒGNUă”ă€ăă«ăăăšăć€æ°**__malloc_hook
ăŻămalloc()
ăćŒăłćșăăăăăłă«ćŒăłćșăăăéąæ°ăźăąăăŹăčăæăăă€ăłăżă§ăăălibcă©ă€ăă©ăȘăźăăŒăżă»ăŻă·ă§ăłă«æ ŒçŽăăăŠăăŸăăăăăăŁăŠăăăźăąăăŹăčăäŸăă°One Gadget**ă§äžæžăăăămalloc
ăćŒăłćșăăăăšăOne GadgetăćŒăłćșăăăŸăă
mallocăćŒăłćșăă«ăŻăăăă°ă©ă ăăăăćŒăłćșăăźăćŸ
ă€ăă**printf("%10000$c")
**ăćŒăłćșăăăšă§ălibc
ăăăŒăă«ăăăăćČăćœăŠăăăă«mallocăćŒăłćșăăăă«ăéćžžă«ć€ăăźăă€ăăćČăćœăŠăăăšăă§ăăŸăă
One Gadgetă«éąăăè©łçŽ°ăŻä»„äžăćç §ăăŠăă ăă:
One GadgetGLIBC >= 2.34ă§ăŻăăăŻăçĄćčă«ăȘăŁăŠăăăăšă«æłšæăăŠăă ăăăææ°ăźGLIBCăăŒăžă§ăłă§äœżçšă§ăăä»ăźæèĄăăăăŸăăćç §: https://github.com/nobodyisnobody/docs/blob/main/code.execution.on.last.libc/README.md.
ăăăŻăæȘæŽćăăłæ»æăæȘçšăăćŸă«ăăĄăčăăăłæ»æăæȘçšăăăăŒăžăźäŸăź1ă€ă§æȘçšăăăŸăă:
Unsorted Bin Attackăă€ăăȘă«ă·ăłăă«ăăăć ŽćăæŹĄăźăłăăłăă§__free_hook
ăźăąăăŹăčăèŠă€ăăăăšăă§ăăŸă:
ăăźæçšżă§ăŻăă·ăłăă«ăȘăă§free hookăźăąăăŹăčăèŠă€ăăăăăźăčăăăăă€ăčăăăăŹă€ăăèŠă€ăăăăšăă§ăăŸăăèŠçŽăăăšăfreeéąæ°ć ă§ïŒ
ćèż°ăźăłăŒăăźăăŹăŒăŻăă€ăłăă§ă$eaxă«ăŻfree hookăźăąăăŹăčăæ ŒçŽăăăŸăă
æŹĄă«ăăăĄăčăăăłæ»æăćźèĄăăăŸăïŒ
ăŸăă__free_hook
ăźć Žæă§ă”ă€ăș200ăźăăĄăčăăăŁăłăŻăæ±ăăăšăćŻèœă§ăăăăšăçșèŠăăăŸăïŒ
$1 = (void (**)(void *, const void *)) 0x7ff1e9e607a8 <__free_hook> gef†x/60gx 0x7ff1e9e607a8 - 0x59
0x7ff1e9e6074f: 0x0000000000000000 0x0000000000000200
0x7ff1e9e6075f: 0x0000000000000000 0x0000000000000000 0x7ff1e9e6076f <list_all_lock+15>: 0x0000000000000000 0x0000000000000000 0x7ff1e9e6077f <_IO_stdfile_2_lock+15>: 0x0000000000000000 0x0000000000000000
ăăźć Žæă§ă”ă€ăș0x200ăźăăĄăčăăăŁăłăŻăććŸă§ăăă°ăćźèĄăăăéąæ°ăă€ăłăżăäžæžăăăăăšăćŻèœă§ăă
ăăźăăă«ăă”ă€ăș0xfc
ăźæ°ăăăăŁăłăŻăäœæăăăăźăă€ăłăżă§ăăŒăžăăăéąæ°ă2ććŒăłćșăăŸăăăăă«ăăăăăĄăčăăăłć
ăźă”ă€ăș0xfc*2 = 0x1f8
ăźè§ŁæŸăăăăăŁăłăŻăžăźăă€ăłăżăććŸăăŸăă
æŹĄă«ăăăźăăŁăłăŻăźç·šééąæ°ăćŒăłćșăăŠăăăźăăĄăčăăăłăź**fd
ăąăăŹăčăćăź__free_hook
**éąæ°ăæăăăă«ć€æŽăăŸăă
ăăźćŸăă”ă€ăș0x1f8
ăźăăŁăłăŻăäœæăăŠăăăĄăčăăăłăăćăźçĄé§ăȘăăŁăłăŻăććŸăăăăă«ă”ă€ăș0x1f8
ăźăăŁăłăŻăäœæăăŠă**__free_hook
ć
ăźăăĄăčăăăłăăŁăłăŻăććŸăăsystem
**éąæ°ăźăąăăŹăčă§äžæžăăăŸăă
æćŸă«ăæćć/bin/sh\x00
ăć«ăăăŁăłăŻăè§ŁæŸăăćé€éąæ°ăćŒăłćșăăŠă**__free_hook
**éąæ°ăăăȘăŹăŒăă/bin/sh\x00
ăăă©ăĄăŒăżăšăăŠsystemăæăăŸăă
AWSăăăăłă°ăćŠăłăćźè·”ăăïŒHackTricks Training AWS Red Team Expert (ARTE) GCPăăăăłă°ăćŠăłăćźè·”ăăïŒHackTricks Training GCP Red Team Expert (GRTE)