RSSAmplifier

Blog

Diary of a reverse-engineer

doar-e.github.ioRSS feed ↗29 posts

Latest posts

Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64

🧾 Introduction After participating in Pwn2Own Austin in 2021 and failing to land my remote kernel exploit Zenith (which you can read about here ), I was eager to try again. It is fun and forces me to look at things I would never have looked at otherwise. The one thing I …

Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup

Introduction Pwn2Own Austin 2021 was announced in August 2021 and introduced new categories, including printers. Based on our previous experience with printers, we decided to go after one of the three models. Among those, the Canon ImageCLASS MF644Cdw seemed like the most interesting target: previous research was limited (mostly targeting …

Competing in Pwn2Own 2021 Austin: Icarus at the Zenith

Introduction In 2021, I finally spent some time looking at a consumer router I had been using for years. It started as a weekend project to look at something a bit different from what I was used to. On top of that, it was also a good occasion to play …

Building a new snapshot fuzzer & fuzzing IDA

Introduction It is January 2020 and it is this time of the year where I try to set goals for myself. I had just come back from spending Christmas with my family in France and felt fairly recharged. It always is an exciting time for me to think and plan …

Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086)

Introduction Since the beginning of my journey in computer security I have always been amazed and fascinated by true remote vulnerabilities. By true remotes, I mean bugs that are triggerable remotely without any user interaction. Not even a single click. As a result I am always on the lookout for …

Modern attacks on the Chrome browser : optimizations and deoptimizations

Introduction Late 2019, I presented at an internal Azimuth Security conference some work on hacking Chrome through it's JavaScript engine. One of the topics I've been playing with at that time was deoptimization and so I discussed, among others, vulnerabilities in the deoptimizer. For my talk at InfiltrateCon 2020 in …

A journey into IonMonkey: root-causing CVE-2019-9810.

A journey into IonMonkey: root-causing CVE-2019-9810. Introduction In May, I wanted to play with BigInt and evaluate how I could use them for browser exploitation. The exploit I wrote for the blazefox relied on a Javascript library developed by @5aelo that allows code to manipulate 64-bit integers. Around the same …

Circumventing Chrome's hardening of typer bugs

Introduction Some recent Chrome exploits were taking advantage of Bounds-Check-Elimination in order to get a R/W primitive from a TurboFan's typer bug (a bug that incorrectly computes type information during code optimization). Indeed during the simplified lowering phase when visiting a CheckBounds node if the engine can guarantee that …

Introduction to TurboFan

Introduction Ages ago I wrote a blog post here called first dip in the kernel pool , this year we're going to swim in a sea of nodes! The current trend is to attack JavaScript engines and more specifically, optimizing JIT compilers such as V8 's TurboFan , SpiderMonkey's IonMonkey, JavaScriptCore's Data …

Introduction to SpiderMonkey exploitation.

Introduction This blogpost covers the development of three exploits targeting SpiderMonkey JavaScript Shell interpreter and Mozilla Firefox on Windows 10 RS5 64-bit from the perspective of somebody that has never written a browser exploit nor looked closely at any JavaScript engine codebase. As you have probably noticed, there has been …

CVE-2017-2446 or JSC::JSGlobalObject::isHavingABadTime.

Introduction This post will cover the development of an exploit for JavaScriptCore (JSC) from the perspective of someone with no background in browser exploitation. Around the start of the year, I was pretty burnt out on CTF problems and was interested in writing an exploit for something more complicated and …

Breaking ledgerctf's AES white-box challenge

Introduction About a month ago, my mate b0n0n was working on the ledgerctf puzzles and challenged me to have a look at the ctf2 binary. I eventually did and this blogpost discusses the protection scheme and how I broke it. Before diving in though, here is a bit of background …

beVX challenge on the operation table

Introduction About two weeks ago, my friend mongo challenged me to solve a reverse-engineering puzzle put up by the SSD team for OffensiveCon2018 (which is a security conference that took place in Berlin in February). The challenge binary is available for download here and here is one of the original …

Debugger data model, Javascript & x64 exception handling

Introduction The main goal of today's post is to show a bit more of what is now possible with the latest Windbg (currently branded "WinDbg Preview" in the Microsoft store) and the time travel debugging tools that Microsoft released a few months ago. When these finally got released, a bit …

Binary rewriting with syzygy, Pt. I

Introduction Binary instrumentation and analysis have been subjects that I have always found fascinating. At compile time via clang , or at runtime with dynamic binary instrumentation frameworks like Pin or DynamoRIO . One thing I have always looked for though, is a framework able to statically instrument a PE image. A …

happy unikernels

Intro Below is a collection of notes regarding unikernels. I had originally prepared this stuff to submit to EkoParty’s CFP, but ended up not wanting to devote time to stabilizing PHP7’s heap structures and I lost interest in the rest of the project before it was complete. However …

Token capture via an llvm-based analysis pass

Introduction About three years ago, the LLVM framework started to pique my interest for a lot of different reasons. This collection of industrial strength compiler technology, as Latner said in 2008, was designed in a very modular way. It also looked like it had a lot of interesting features that …

Keygenning with KLEE

Introduction In the past weeks I enjoyed working on reversing a piece of software (don't ask me the name), to study how serial numbers are validated. The story the user has to follow is pretty common: download the trial, pay, get the serial number, use it in the annoying nag …

Spotlight on an unprotected AES128 white-box implementation

Introduction I think it all began when I've worked on the NSC2013 crackme made by @elvanderb , long story short you had an AES128 heavily obfuscated white-box implementation to break. The thing was you could actually solve the challenge in different ways: the first one was the easiest one: you didn't …

Taming a wild nanomite-protected MIPS binary with symbolic execution: No Such Crackme

As last year, the French conference No Such Con returns for its second edition in Paris from the 19th of November until the 21th of November. And again, the brilliant Eloi Vanderbeken & his mates at Synacktiv put together a series of three security challenges especially for this occasion. Apparently, the …

Dissection of Quarkslab's 2014 security challenge

Introduction As the blog was a bit silent for quite some time, I figured it would be cool to put together a post ; so here it is folks, dig in! The French company Quarkslab recently released a security challenge to win a free entrance to attend the upcoming HITBSecConf conference …

Corrupting the ARM Exception Vector Table

Introduction A few months ago, I was writing a Linux kernel exploitation challenge on ARM in an attempt to learn about kernel exploitation and I thought I'd explore things a little. I chose the ARM architecture mainly because I thought it would be fun to look at. This article is …

Deep dive into Python's VM: Story of LOAD_CONST bug

Introduction A year ago, I've written a Python script to leverage a bug in Python's virtual machine: the idea was to fully control the Python virtual processor and after that to instrument the VM to execute native codes. The python27_abuse_vm_to_execute_x86_code.py script wasn't really self-explanatory, so I believe only a …

First dip into the kernel pool : MS10-058

Introduction I am currently playing with pool-based memory corruption vulnerabilities. That’s why I wanted to program a PoC exploit for the vulnerability presented by Tarjei Mandt during his first talk “Kernel Pool Exploitation on Windows 7” [3] . I think it's a good exercise to start learning about pool overflows …

Having a look at the Windows' User/Kernel exceptions dispatcher

Introduction The purpose of this little post is to create a piece of code able to monitor exceptions raised in a process (a bit like gynvael 's ExcpHook but in userland), and to generate a report with information related to the exception. The other purpose is to have a look …

Breaking Kryptonite's obfuscation: a static analysis approach relying on symbolic execution

Introduction Kryptonite was a proof-of-concept I built to obfuscate codes at the LLVM intermediate representation level. The idea was to use semantic-preserving transformations in order to not break the original program. One of the main idea was for example to build a home-made 32 bits adder to replace the add …

Pinpointing heap-related issues: OllyDbg2 off-by-one story

Introduction Yesterday afternoon, I was peacefully coding some stuff you know but I couldn't make my code working. As usual, in those type of situations you fire up your debugger in order to understand what is going on under the hood. That was a bit weird, to give you a …

Some thoughts about code-coverage measurement with Pin

Introduction Sometimes, when you are reverse-engineering binaries you need somehow to measure, or just to have an idea about how much "that" execution is covering the code of your target. It can be for fuzzing purpose, maybe you have a huge set of inputs (it can be files, network traffic …

Regular expressions obfuscation under the microscope

Introduction Some months ago I came across a strange couple of functions that was kind of playing with a finite-state automaton to validate an input. At first glance, I didn't really notice it was in fact a regex being processed, that's exactly why I spent quite some time to understand …