[00:00.000 --> 00:10.420] ...challenge that turns any bytecode into a printable ASCII loader that will do the equivalent of that bytecode. [00:12.780 --> 00:15.620] So... oh, that's what I said. [00:17.240 --> 00:18.700] What can you use that for? [00:18.800 --> 00:22.920] You can use it for voting IDS or for sneaking code into buffers, whatever. [00:25.940 --> 00:32.720] So basically the way it works is, like I said, the ASCII... actually, let me... [00:36.520 --> 00:37.720] okay, so... [00:48.750 --> 00:50.390] So that's just a piece of shell code, right? [00:51.990 --> 00:54.850] And then it [00:58.210 --> 00:59.410] makes it into something like that. [01:01.310 --> 01:02.550] So let's go back to the thing. [01:05.350 --> 01:08.270] So it actually does it just using four instructions. [01:08.690 --> 01:16.070] Push EAX, pop ESP, and subtract and add instructions for EAX and EAX. [01:17.250 --> 01:21.310] Are you guys all familiar with how memory works in the stack? [01:22.230 --> 01:27.890] It's just different segments, and when you do an overflow, you're just overwriting the return address. [01:29.070 --> 01:30.070] Everyone cool with that? [01:30.490 --> 01:32.470] And everyone cool with registers? [01:33.410 --> 01:43.950] Like, the stack is a structure that keeps stack frames, and... so you've got the heap in the stack, and the stack grows this way, while the heap grows this way. [01:44.090 --> 01:46.390] And you've got the text segment, which is up higher. [01:47.450 --> 01:55.270] When you do, like, a stack overflow, you're tricking the execution pointer into going into stack memory, where you have your shellcode. [01:55.270 --> 02:01.630] So you've got EIP, the execution pointer, and ESP, both in the stack. [02:03.210 --> 02:04.990] So... okay, so yeah. [02:05.630 --> 02:13.610] Push EAX will write whatever value of EAX is into the stack by pushing those four bytes onto the stack. [02:13.710 --> 02:20.450] Each time you push, it builds towards lower addresses, because the stack builds backwards. [02:21.930 --> 02:30.190] And then pop ESP will take whatever value is at ESP, actually, and write it back into ESP as the register. [02:31.650 --> 02:52.030] So... if you look at those four instructions, and you assemble them, and then you look at them just in a text editor, where you see that push EAX is capital P, which is easy to remember, pop ESP is its backslash, and subtract EAX is the minus sign, followed by the four byte word, [02:52.070 --> 02:53.630] which you're subtracting from EAX. [02:54.670 --> 02:55.550] And... and... [02:55.550 --> 02:56.330] Are you reading this thing? [02:57.110 --> 02:57.890] Right there. [02:58.410 --> 02:58.770] Off... [03:00.890 --> 03:07.310] Oh, if you look at the very bottom, she assembled push EAX, pop ESP, sub EAX from... [03:07.770 --> 03:11.990] 41, 41, 41, 41, which is capital A, and you do it for those four instructions. [03:12.210 --> 03:19.390] When you assemble it, the assembled machine code actually is in a printable range. [03:21.670 --> 03:23.430] So, those are those four instructions, right? [03:24.530 --> 03:25.150] Everyone good? [03:25.290 --> 03:26.390] Any questions so far? [03:27.510 --> 03:28.310] All right. [03:29.590 --> 03:30.230] All right. [03:31.570 --> 03:32.210] Okay. [03:32.210 --> 03:34.290] So, those are the four instructions written out. [03:35.890 --> 03:47.750] And as long as you use printable values for the words that you're subtracting or adding from EAX, you can use all printable ASCII instructions. [03:48.930 --> 03:51.570] So, the way the loader actually works is... [03:52.570 --> 04:00.250] So, since the stack moves this way, and EIP goes this way, if you... [04:00.250 --> 04:06.990] Basically what the loader does is it's going to build the bytecode onto the stack by pushing it. [04:07.390 --> 04:09.410] So, it's basically writing... [04:09.410 --> 04:16.510] It's going to write the bytecode onto the stack backwards from ESP moving back. [04:16.510 --> 04:23.950] So, what you want to do is you want to first set the stack pointer somewhere after your loader code. [04:24.430 --> 04:27.590] And then as EIP goes through there... [04:28.250 --> 04:30.770] So, the way you set ESP is... [04:31.830 --> 04:34.770] First you get EAX to whatever value you want ESP to be. [04:35.030 --> 04:37.550] And then push EAX and then pop ESP. [04:37.790 --> 04:39.790] And you can do that all with those four instructions. [04:40.290 --> 04:47.910] The way you set EAX to arbitrary values is you just keep subtracting printable values from it until it wraps around to whatever value you want. [04:48.350 --> 04:50.290] You can usually do it in... [04:50.290 --> 04:55.290] You can get to about any value in one to three subtractions. [04:56.270 --> 04:58.290] Three is the maximum that you'll ever have to do. [04:59.050 --> 05:02.050] So, then you set EAX to where you want ESP to be. [05:02.250 --> 05:02.870] You set ESP. [05:03.230 --> 05:11.110] And then after you do that, you set EAX to the last four bytes of your bytecode. [05:11.370 --> 05:12.930] And you push that to the stack. [05:12.930 --> 05:21.210] Then you subtract more values from EAX to wrap it around again to the second-to-last four bytes of your bytecode and push that to the stack again. [05:21.430 --> 05:22.830] And you just keep doing that. [05:23.070 --> 05:31.630] And as EIP reads through the loader code this way, it's building the bytecode backwards towards EIP. [05:32.090 --> 05:42.150] And if you set ESP to be right at the end of your loader code, plus the number of bytes of the bytecode that you're building. [05:46.410 --> 05:52.170] At the end of your loader code, at the last push instruction, EIP and ESP will meet at the same address. [05:52.610 --> 05:55.330] And EIP will just flow into the newly built bytecode. [05:57.110 --> 05:58.550] There are a couple things you've got to watch out for. [05:58.830 --> 06:04.550] Like, if it's not a multiple of four, since you can only push four byte words, you've got to pad it with no ops and stuff. [06:06.350 --> 06:07.890] But, yeah, that's basically the technique. [06:10.590 --> 06:14.050] Oh, and then to start it out, you have to zero EAX somehow. [06:14.050 --> 06:21.530] So, the way you zero it is by ending two conflicting bit values and do that. [06:21.670 --> 06:23.050] You can ensure that... [06:23.050 --> 06:29.270] Like, if you and any value with A and 8, you'll always get zero. [06:29.510 --> 06:32.310] Because if you look at the bits, they... [06:33.170 --> 06:34.970] Yeah, you guys know and operation. [06:37.710 --> 06:38.570] Yeah, okay. [06:38.690 --> 06:45.050] And then also, if you can't be exact with putting your ESP where you want it, you can just sort of guesstimate and throw it somewhere. [06:45.370 --> 06:54.350] And then, after you've built your bytecode, you just wrap EAX around to be 0x90909090. [06:54.650 --> 07:01.910] And then, with every one byte of push instruction, you build four bytes of no-op sled. [07:02.130 --> 07:04.590] So, it can build back to itself really quickly. [07:04.850 --> 07:14.890] And then, you just make a second no-op sled to bridge from the end of the loader code to the newly built bytecode. [07:17.390 --> 07:17.830] Right. [07:22.820 --> 07:23.260] Whoops. [07:37.580 --> 07:38.460] Digital blasphemy. [07:44.090 --> 07:45.890] I don't know what the hell just happened to that. [08:03.830 --> 08:04.310] There you go. [08:04.430 --> 08:04.570] Okay. [08:09.260 --> 08:09.700] Okay. [08:09.900 --> 08:12.580] So, here's a really simple program, right, that's vulnerable. [08:21.350 --> 08:22.990] So, just to make sure I know what we're doing. [08:51.050 --> 08:53.150] Can you put the text a little bit bigger? [08:55.190 --> 08:56.510] That's as big as it gets. [08:57.490 --> 08:57.830] Huge. [09:01.950 --> 09:03.910] Go to console mode, I guess, but I don't think... [09:09.750 --> 09:11.370] Resolution would be a pain in the ass to do, though. [09:12.790 --> 09:14.070] Can you guys... [09:14.070 --> 09:14.750] Oh, man. [09:19.410 --> 09:19.890] Okay. [09:20.370 --> 09:22.210] Well, it's a root shell. [09:23.050 --> 09:24.870] This is just a standard exploit, right? [09:25.530 --> 09:28.410] Just shove the shellcode into an environment variable. [09:28.710 --> 09:32.270] And then, overwrite return address with whatever the crap that is, right? [09:38.630 --> 09:39.830] Oh, yeah, crap. [09:41.310 --> 09:43.150] I got flyers and crap for you guys. [09:46.030 --> 09:47.590] So, that's a really simple one, right? [09:48.270 --> 09:53.350] Then, this one's a little bit harder because it does filtering of arguments. [09:54.050 --> 10:00.550] If you look at the is print, it will only allow printable characters for the second argument. [10:18.130 --> 10:25.050] So, okay, tried to put shellcode into the second argument, but you couldn't because, well, it won't allow it. [10:25.210 --> 10:30.130] And this one clears out all the environment variables, so you can't put your shellcode in the environment anymore. [10:30.710 --> 10:35.750] So, somehow, you've got to get shellcode into that buffer that only allows printable characters. [10:40.980 --> 10:42.700] So, that will fit in there. [10:52.490 --> 10:53.250] Wait, hold on. [10:55.330 --> 10:55.730] Okay. [10:55.890 --> 11:02.090] So, the capital dash N switch will optimize, which will just set ESP to be exactly at the right point. [11:02.270 --> 11:03.930] So, it doesn't have to build the crazy no-op bridge. [11:07.010 --> 11:14.090] And it writes all that top stuff out to standard error and it only writes the shellcode to standard out. [11:14.250 --> 11:17.590] So, you can just use it in like this. [11:28.360 --> 11:34.620] So, the reason that crashed right there is because it didn't know where to set ESP. [11:34.620 --> 11:36.320] So, it just sent it to the very end of the stack. [11:36.900 --> 11:42.920] So, in this case, the no-ops lead wasn't big enough to get to the newly built bytecode. [11:43.140 --> 11:45.660] So, it just falls off the end of the loader and crashes. [11:57.430 --> 11:57.850] Oops. [12:09.740 --> 12:10.740] Oh, I know what's wrong. [12:17.100 --> 12:17.740] There we go. [12:19.860 --> 12:20.260] Yeah. [12:20.260 --> 12:21.840] So, yeah. [12:22.400 --> 12:25.400] That time, you gave it the right target address. [12:26.500 --> 12:27.300] And it... [12:28.400 --> 12:29.720] Well, you guys know what it did, right? [12:29.860 --> 12:31.560] Do you guys have any questions so far with that? [12:31.740 --> 12:33.300] Or do I need to explain that? [12:34.900 --> 12:43.680] It just built the bytecode and then there was actually a point where EIP and ESP met and it flowed right into the bytecode. [12:43.680 --> 12:48.540] And then there's an even more restrictive one that... [12:48.540 --> 12:51.060] So, this one's... [13:02.120 --> 13:04.800] It's got to be SUID to exploit it. [13:16.290 --> 13:17.050] Okay. [13:17.150 --> 13:21.650] So, this one only allows a very, very restrictive character set. [13:23.950 --> 13:33.190] But that's okay because you can define the character set as long as you escape everything properly. [13:40.780 --> 13:42.320] Let's use a smaller piece of that. [13:46.330 --> 13:46.850] Okay. [13:47.090 --> 13:50.590] So, this just used a smaller character set, only 12 characters. [13:50.590 --> 13:56.070] And when it finishes, it gets to 185 bytes. [13:57.550 --> 13:58.790] I hope this one works. [13:58.930 --> 13:59.950] It's one of those weird conditions. [14:01.150 --> 14:03.550] Just because memory happens to be in a weird place here. [14:44.320 --> 14:44.660] Oops. [14:45.580 --> 14:46.260] See, sometimes... [14:46.260 --> 14:46.400] Okay. [14:47.020 --> 14:50.980] Sometimes it'll move because the bytecode changed in length. [14:51.280 --> 14:54.840] Before it was 264 bytes long and then this time it's 259. [14:56.240 --> 15:03.040] That's just because it's trying to find sets of values that it can subtract to wrap around. [15:03.700 --> 15:07.220] And sometimes, you know, you have to use three instead of two. [15:07.960 --> 15:12.060] Depending on what the bytecode is and where it is in memory to begin with. [15:15.580 --> 15:18.560] And hopefully this isn't one of the ones that constantly switches between the two. [15:18.700 --> 15:19.700] Oh, there we go. [15:22.340 --> 15:26.700] So, if you want to look at what that actual bytecode looks like. [15:31.420 --> 15:32.840] Let's just do this actually. [15:41.720 --> 15:49.440] So, there it is using only capital A percent P and then, you know, those restrictive characters. [15:52.940 --> 15:53.420] Okay. [15:53.600 --> 16:00.980] And then, the last thing I have is, I've got some challenge code on firewall as a website. [16:01.580 --> 16:03.440] And one of the challenges is this one. [16:05.340 --> 16:07.360] Basically, it clears out all the memory. [16:08.260 --> 16:11.260] So, you've got nowhere to put your shellcode at all. [16:12.260 --> 16:13.820] It's just sort of a pain in the ass. [16:23.840 --> 16:24.400] Oops. [17:03.160 --> 17:04.920] So, if you look at the stack. [17:05.680 --> 17:05.760] Oh. [17:08.960 --> 17:09.880] Let's do strings. [17:15.200 --> 17:16.000] Why isn't it cleared? [17:20.580 --> 17:20.900] Oh. [17:20.960 --> 17:21.040] Okay. [17:21.100 --> 17:22.100] Here's all the environment stuff. [17:22.140 --> 17:23.220] And here's where it's all zeroed. [17:23.840 --> 17:25.740] So, you see a whole lot of nothing, right? [17:35.370 --> 17:36.010] Except for... [17:36.710 --> 17:37.030] Oops. [17:55.180 --> 17:55.530] All right. [17:55.560 --> 17:56.380] I'm trying to get to the end. [17:59.580 --> 17:59.900] Okay. [18:00.600 --> 18:01.080] So... [18:04.200 --> 18:04.680] Ah. [18:06.040 --> 18:07.060] That's what I was looking for. [18:08.580 --> 18:18.880] So, if you look at the very end of the memory, at the very end, there's the name of the program that's running. [18:20.260 --> 18:23.940] So, that's the one thing that you can control, really. [18:28.500 --> 18:30.240] So, if you can control that. [18:33.700 --> 18:34.180] Oh. [18:34.360 --> 18:37.020] So, there's another piece of shellcode. [18:37.140 --> 18:37.880] It's just a little bit smaller. [18:43.180 --> 18:50.540] So, what we're going to do is we're going to make a symlink using this to the program. [18:50.540 --> 18:59.560] And then, we're going to make, we're going to exploit it by making execution pointer return back into the name of the program that's running. [18:59.840 --> 19:03.320] Which will build the bytecode onto the very end of the stack. [19:03.900 --> 19:07.360] So, the problem here is we have to make sure we save enough space at the end of the stack. [19:07.740 --> 19:10.180] Otherwise, we're going to be building right into our loader code. [19:13.440 --> 19:16.480] So, 40 bytes should be good enough. [19:16.480 --> 19:17.980] So, that's 201. [19:19.040 --> 19:25.400] And we're building from BFFFFA. [19:25.660 --> 19:28.020] So, subtract 201. [19:29.280 --> 19:32.700] And, oops. [19:46.690 --> 19:49.810] I'm going to make this vulnerable first. [19:53.550 --> 19:54.210] Okay. [19:54.210 --> 20:00.990] So, summer-b40 tiny shell. [20:05.410 --> 20:07.570] So, we've got this crazy thing. [20:09.730 --> 20:15.290] If you run that crazy thing and, what did I say? [20:15.510 --> 20:15.890] 31. [20:18.430 --> 20:24.190] So, we just return into where this thing is going to start. [20:27.870 --> 20:28.650] And... [20:28.650 --> 20:29.230] Ha ha. [20:29.850 --> 20:30.390] Root. [20:33.590 --> 20:34.370] And... [20:34.370 --> 20:35.590] That's basically it. [20:35.610 --> 20:39.030] Do you guys have any questions about options or anything? [20:41.070 --> 20:41.850] Shoot. [20:41.850 --> 20:43.230] If Bob. [20:43.810 --> 20:50.910] I'm saying, you're holding me to the access to the computer and I want to go in December to change it. [20:52.270 --> 21:00.310] Is it something I could just go transfer to December over there and start going or is it a bit more of a process to get to something you want? [21:00.350 --> 21:02.450] Oh, it's just really simple. [21:04.550 --> 21:05.030] Yeah. [21:05.610 --> 21:06.870] I'll show you guys the code. [21:09.290 --> 21:11.050] Basically, yeah, it's just really simple. [21:11.750 --> 21:21.450] All it's doing is it's reading through the bytecode and first it sees if it's in chunks of four and if not, it pads with no ops. [21:21.450 --> 21:24.150] And then it... [21:24.150 --> 21:26.030] I use... [21:26.030 --> 21:29.570] You guys ever see this function stir fry or string fry? [21:29.710 --> 21:33.150] It just makes anagrams out of strings. [21:34.210 --> 21:36.750] So, I use that to randomize the character set. [21:36.750 --> 21:44.150] So, every time you do it, it's a little bit different. [21:45.210 --> 21:49.350] Because it's just picking random characters that will fit into whatever. [21:53.550 --> 21:56.130] Yeah, so it's pretty simple code. [21:58.550 --> 22:00.190] Any other questions? [22:02.790 --> 22:08.390] Like, if you're doing it on a remote system, like, it's probably really only useful for local exploits. [22:08.450 --> 22:09.390] I can't think of... [22:09.390 --> 22:20.710] Like, unless you know where something's going to be happening in memory or, like, if you can build a big enough no-op sled and you know that you're about where you're supposed to be, you can use it remotely. [22:21.030 --> 22:22.370] But other than that, not really. [22:24.490 --> 22:26.110] Anyone else have any other questions? [22:33.010 --> 22:33.910] I don't know. [22:37.090 --> 22:37.890] Maybe it's possible. [22:38.170 --> 22:39.110] I haven't... [22:40.330 --> 22:42.090] I haven't looked into the instructions there. [22:42.930 --> 22:44.110] This is just for... [22:47.650 --> 22:48.000] Well... [22:50.020 --> 22:51.680] This does it only using four instructions. [22:52.390 --> 22:53.240] No, I won't. [22:53.280 --> 22:53.940] I mean, I get that. [22:54.120 --> 22:57.140] But under alpha, I don't know that it's instructions. [22:57.680 --> 22:59.220] When you assemble them. [22:59.520 --> 23:00.000] Yeah. [23:00.780 --> 23:06.180] It's just a question of, you know, the subset of instructions that are also printable. [23:07.460 --> 23:08.560] You're limited to those. [23:08.680 --> 23:10.800] And if you can figure out a way to do it using those, then great. [23:11.220 --> 23:11.540] But... [23:11.540 --> 23:13.020] I was just wondering if you actually have them. [23:13.060 --> 23:13.320] Oh. [23:14.220 --> 23:15.100] No, I don't. [23:15.700 --> 23:16.140] I didn't... [23:17.920 --> 23:18.400] Wow. [23:20.160 --> 23:20.960] Anyone else? [23:21.820 --> 23:22.300] Questions? [23:22.300 --> 23:22.420] Questions. [23:25.400 --> 23:25.720] Oh. [23:25.880 --> 23:28.280] I talk about all this crap in a book, too. [23:28.540 --> 23:30.520] And I'm supposed to hand out some things if you guys want them. [23:31.240 --> 23:34.520] But if anyone else has any other questions, shoot. [23:34.660 --> 23:36.160] Otherwise, I'm going to break these things out. [23:41.720 --> 23:43.920] Does this work on Microsoft systems? [23:44.100 --> 23:45.200] On Microsoft systems? [23:45.360 --> 23:46.200] Exactly the same way. [23:46.320 --> 23:47.780] I mean, it's just... [23:47.780 --> 23:49.420] This is architecture level, so... [23:53.340 --> 23:55.980] I guess it would work the same way. [23:56.200 --> 23:57.760] You just have to change the memory addresses. [24:00.840 --> 24:04.100] Because it doesn't use any syscalls or anything. [24:06.180 --> 24:06.620] So... [24:06.620 --> 24:08.100] I mean, it should be able to... [24:08.680 --> 24:13.720] Like, on Microsoft systems, you'll be able to build bytecode using this. [24:14.280 --> 24:15.180] Just the same way. [24:15.280 --> 24:18.140] You just have to make sure you use bytecode that doesn't use the Linux syscalls. [24:23.720 --> 24:24.160] So... [24:24.160 --> 24:25.120] I guess that's it. [24:25.200 --> 24:26.600] Anyone have anything else? [24:27.640 --> 24:28.080] Shoot. [24:32.460 --> 24:32.900] Yeah. [24:33.180 --> 24:33.480] It's... [24:33.480 --> 24:35.260] This is posted on phiral.com. [24:36.260 --> 24:38.220] P-H-I-R-A-L. [24:41.080 --> 24:41.440] And... [24:42.700 --> 24:43.060] Yeah. [24:43.320 --> 24:43.900] If you want... [24:43.900 --> 24:45.860] You can import this to other architectures really easily. [24:46.100 --> 24:46.880] One guy did it. [24:47.480 --> 24:47.840] Except... [24:47.840 --> 24:49.480] Stir-fry isn't in. [24:49.720 --> 24:51.200] Like, the BSD stuff. [24:51.540 --> 24:51.900] So... [24:51.900 --> 24:54.780] You just make a little function that randomizes a string. [24:55.780 --> 24:56.800] It's really a simple code. [24:57.380 --> 24:59.260] I just liked it because I thought it was a funny name. [25:06.020 --> 25:06.440] All right. [25:06.500 --> 25:08.560] So I got a bunch of those things if you guys want them. [25:08.620 --> 25:11.140] They're just little handouts, I guess. [25:12.420 --> 25:13.840] It's a shameless promotion. [25:17.040 --> 25:17.760] All right. [25:17.880 --> 25:18.600] I guess that's it. [25:18.900 --> 25:19.780] Unless anyone... [25:19.780 --> 25:20.100] All right. [25:20.300 --> 25:20.640] Cool. [25:20.640 --> 25:20.820] All right. [25:21.000 --> 25:21.020] All right.