Practical Windows XP - 2003 Heap Exploitation.pdf

(806 KB) Pobierz
Practical Windows XP/2003 Heap Exploitation
Blackhat USA 2009
John McDonald (jrmcdona@us.ibm.com)
Chris Valasek (cvalasek@us.ibm.com)
IBM ISS X-Force Research
Practical Windows XP/2003 Heap Exploitation
2
Table of Contents
Practical Windows XP/2003 Heap Exploitation ....................................................................... 1
Table of Contents ...................................................................................................................... 3
Introduction ............................................................................................................................... 5
Overview ............................................................................................................................... 6
Prior Work ............................................................................................................................ 6
Fundamentals ............................................................................................................................ 8
Architecture........................................................................................................................... 9
Front-End Manager ........................................................................................................... 9
Back-End Manager ........................................................................................................... 9
Virtual Memory .................................................................................................................. 10
Reservation and Commitment......................................................................................... 10
Heap Base ........................................................................................................................... 11
Memory Management ......................................................................................................... 12
Heap Segments................................................................................................................ 13
Segment Base .................................................................................................................. 13
UCR Tracking ................................................................................................................. 14
Front End Manager ............................................................................................................. 15
Look-Aside List (LAL) ................................................................................................... 15
Low Fragmentation Heap (LFH) .................................................................................... 16
Back End Manager .............................................................................................................. 17
Freelists ........................................................................................................................... 17
Freelist Bitmap ................................................................................................................ 17
Heap Cache ..................................................................................................................... 18
Virtual Alloc List ............................................................................................................ 19
Core Algorithms.................................................................................................................. 20
Allocation Search ............................................................................................................ 20
Unlinking ........................................................................................................................ 22
Linking ............................................................................................................................ 23
Coalescing ....................................................................................................................... 24
Security Mechanisms .......................................................................................................... 27
Heap Cookie.................................................................................................................... 27
Safe Unlinking ................................................................................................................ 27
Process Termination........................................................................................................ 28
Tactics ..................................................................................................................................... 30
Lookaside List Link Overwrite ........................................................................................... 30
Bitmap Flipping Attack....................................................................................................... 32
FreeList[0] Techniques ....................................................................................................... 34
Searching......................................................................................................................... 34
Linking ............................................................................................................................ 35
Tactics - New Techniques....................................................................................................... 37
Heap Cache ......................................................................................................................... 37
Overview ......................................................................................................................... 37
Heap Cache Invocation ................................................................................................... 37
De-committing Policy ..................................................................................................... 38
Practical Windows XP/2003 Heap Exploitation
3
De-synchronization ......................................................................................................... 39
Basic De-synchronization Attack ................................................................................... 40
De-synchronization ......................................................................................................... 44
Insert Attack .................................................................................................................... 46
De-synchronization Size Targeting................................................................................. 50
Malicious Cache Entry Attack ........................................................................................ 52
Bitmap XOR Attack ............................................................................................................ 59
Avoiding Crashes ................................................................................................................ 61
Lookaside List Exception Handler...................................................................................... 63
Strategy ................................................................................................................................... 66
Application or Heap-Meta?................................................................................................. 66
Multiple Dimensions........................................................................................................... 67
Determinism ........................................................................................................................ 69
Heap Spraying ................................................................................................................. 69
Heap Feng Shui ............................................................................................................... 70
Memory Leaks .................................................................................................................... 72
General Process ................................................................................................................... 73
1. State of Nature ............................................................................................................ 73
2. Action Correlation ...................................................................................................... 73
3. Heap Normalization .................................................................................................... 75
4. Fixing in Contiguous Memory .................................................................................... 77
5. Fixing in Logical Lists ................................................................................................ 78
6. Corruption ................................................................................................................... 78
7. Exploitation ................................................................................................................. 79
Conclusion .............................................................................................................................. 80
Bibliography ........................................................................................................................... 82
Practical Windows XP/2003 Heap Exploitation
4
Introduction
The era of straightforward heap exploitation is now well behind us. Heap exploitation
has steadily increased in difficulty since its genesis in Solar Designer's ground-
breaking Bugtraq post in July of 2000. This trend towards increasingly complicated
exploitation is primarily a result of the widespread implementation of technical heap
counter-measures in modern systems software. The effort required to write reliable
heap exploits has steadily increased due to other factors as well: applications have
become increasingly multi-threaded to take advantage of trends in hardware, and —
in certain code — memory corruption vulnerabilities have become more nuanced and
unique as a result of common, straightforward vulnerability patterns slowly but surely
being audited out of existence.
The end result of all these defensive machinations is that now, more than ever, you
need a fluid, application-aware approach to heap exploitation. The building blocks of
such an approach are an extensive working knowledge of heap internals, an
understanding of the contributing factors in heap determinism, various tactics for
creating predictable patterns in heap memory, and, naturally, a collection of
techniques for exploiting myriad different specific types of memory corruption in
heap memory.
This paper is chiefly concerned with developing this foundational knowledge,
focusing on the practical challenges of heap exploitation on Windows XP SP3 and
Server 2003. Our first goal is to bring the reader up to speed on Windows Heap
Manager internals and the current best of breed exploitation techniques. Once this
foundation is established, we introduce new techniques and original research, which,
at the end of the day, can turn seemingly bleak memory corruption situations into
exploitable conditions. We close out the discussion by looking at Windows heap
exploitation from a more general perspective, and discuss leveraging existing tools
and techniques as part of one‘s approach.
Practical Windows XP/2003 Heap Exploitation
5
Zgłoś jeśli naruszono regulamin