{"id":135,"date":"2007-09-24T20:34:41","date_gmt":"2007-09-25T04:34:41","guid":{"rendered":"http:\/\/outflux.net\/blog\/archives\/2007\/09\/24\/0x41-0x41-0x41-0x41\/"},"modified":"2007-09-24T20:34:41","modified_gmt":"2007-09-25T04:34:41","slug":"0x41-0x41-0x41-0x41","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2007\/09\/24\/0x41-0x41-0x41-0x41\/","title":{"rendered":"0x41 0x41 0x41 0x41"},"content":{"rendered":"<p>When trying to find buffer overflows, it is common practice to try and fill memory with lots of &#8220;A&#8221; characters.  I first saw this when learning basic stack smashing techniques from <a href=\"http:\/\/www.phrack.org\/issues.html?issue=49&#038;id=14#article\">Smashing the Stack for Fun and Profit<\/a>, and have long wondered who did it first.  Ever since, I&#8217;ve always used long strings of &#8220;A&#8221;s too (sometimes &#8220;B&#8221;s), and only recently started using better things like Metasploit&#8217;s <a href=\"http:\/\/metasploit.com\/svn\/framework3\/trunk\/tools\/pattern_create.rb\">pattern generator<\/a> and <a href=\"http:\/\/metasploit.com\/svn\/framework3\/trunk\/tools\/pattern_offset.rb\">offset reporter<\/a>.<\/p>\n<p>I&#8217;m fairly used to seeing things like this from my gdb sessions:<\/p>\n<blockquote><p>\nProgram received signal SIGSEGV, Segmentation fault.<br \/>\n0x41414141 in ?? ()<br \/>\n(gdb)\n<\/p><\/blockquote>\n<p>It means I&#8217;ve managed to gain control of the instruction pointer, and I&#8217;m now to the stage of needing to locate and deliver a shellcode.<\/p>\n<p>Over the weekend I had the pleasure of causing my kernel to do something similar, via an unprivileged userspace process, using the <a href=\"http:\/\/marc.info\/?l=full-disclosure&#038;m=119062587407908&#038;w=2\">vulnerability discovered<\/a> by Wojciech Purczynski:<\/p>\n<blockquote><p>\n[119647.578349] general protection fault: 0000 [3] SMP<br \/>\n[119647.578357] CPU 0<br \/>\n&#8230;<br \/>\n[119647.578759] Code:  Bad RIP value.<br \/>\n[119647.578774] RIP  [&lt;4141414141414141&gt;]\n<\/p><\/blockquote>\n<p>I hadn&#8217;t had an opportunity to play with <a href=\"http:\/\/fist.immunitysec.com\/pipermail\/dailydave\/2007-March\/004133.html\">kernel shellcode<\/a> before, so I ended up learning a lot from Brad Spengler.  Before the day was up, I was left staring at a root shell.<\/p>\n<p>This was a nasty bug.  Luckily, it&#8217;s &#8220;only&#8221; a local exploit, and only for x86_64 kernels.  But that&#8217;s still a very large number of installations.  Please make sure your x86_64 machines are <a href=\"http:\/\/git.kernel.org\/?p=linux\/kernel\/git\/torvalds\/linux-2.6.git;a=commitdiff;h=176df2457ef6207156ca1a40991c54ca01fef567\">patched<\/a> against <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-4573\">CVE-2007-4573<\/a> (for Ubuntu, this is <a href=\"http:\/\/www.ubuntu.com\/usn\/usn-518-1\">USN-518-1<\/a>).<\/p>\n<p style='text-align:left'>&copy; 2007, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>When trying to find buffer overflows, it is common practice to try and fill memory with lots of &#8220;A&#8221; characters. I first saw this when learning basic stack smashing techniques from Smashing the Stack for Fun and Profit, and have long wondered who did it first. Ever since, I&#8217;ve always used long strings of &#8220;A&#8221;s [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,14,12],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/135"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=135"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/135\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}