COMMON ATTACK PATTERN ENUMERATION AND CLASSIFICATIONMITRE canlı kaydı
CAPEC-100
Overflow Buffers
Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an adversary. As a consequence, an adversary is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the adversaries' choice.
Soyutlama
Standard
Tipik ciddiyet
Very High
Saldırı ihtimali
High
Saldırıyı anla
Bu saldırı kalıbı nedir?
Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an adversary. As a consequence, an adversary is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the adversaries' choice.
Uygulama akışı
Saldırı adım adım nasıl ilerler?
Explore
Identify target application
The adversary identifies a target application or program to perform the buffer overflow on. Adversaries often look for applications that accept user input and that perform manual memory management.
Experiment
Find injection vector
The adversary identifies an injection vector to deliver the excessive content to the targeted application's buffer.
Kullanılan teknikler
- Provide large input to a program or application and observe the behavior. If there is a crash, this means that a buffer overflow attack is possible.
Craft overflow content
The adversary crafts the content to be injected. If the intent is to simply cause the software to crash, the content need only consist of an excessive quantity of random data. If the intent is to leverage the overflow for execution of arbitrary code, the adversary crafts the payload in such a way that the overwritten return address is replaced with one of the adversary's choosing.
Kullanılan teknikler
- Create malicious shellcode that will execute when the program execution is returned to it.
- Use a NOP-sled in the overflow content to more easily "slide" into the malicious code. This is done so that the exact return address need not be correct, only in the range of all of the NOPs
Exploit
Overflow the buffer
Using the injection vector, the adversary injects the crafted overflow content into the buffer.
Gereksinimler
Saldırının gerçekleşmesi için ne gerekir?
Ön koşullar
- Targeted software performs buffer operations.
- Targeted software inadequately performs bounds-checking on buffer operations.
- Adversary has the capability to influence the input to buffer operations.
Gerekli beceri
- Low: In most cases, overflowing a buffer does not require advanced skills beyond the ability to notice an overflow and stuff an input variable with content.
- High: In cases of directed overflows, where the motive is to divert the flow of the program or application as per the adversaries' bidding, high level skills are required. This may involve detailed knowledge of the target system architecture and kernel.
Gerekli kaynak
- None: No specialized resources are required to execute this type of attack. Detecting and exploiting a buffer overflow does not require any resources beyond knowledge of and access to the target system.
Tespit
Saldırının göstergeleri nelerdir?
An attack designed to leverage a buffer overflow and redirect execution as per the adversary's bidding is fairly difficult to detect. An attack aimed solely at bringing the system down is usually preceded by a barrage of long inputs that make no sense. In either case, it is likely that the adversary would have resorted to a few hit-or-miss attempts that will be recorded in the system event logs, if they exist.
Etki
Başarılı saldırı neye yol açar?
Unreliable Execution
Etkilenen alanlar: Availability
Execute Unauthorized Commands
Etkilenen alanlar: Confidentiality, Integrity, Availability
Gain Privileges
Etkilenen alanlar: Confidentiality, Access Control, Authorization
Savunma
Nasıl önlenir ve etkisi azaltılır?
1
Use a language or compiler that performs automatic bounds checking.
2
Use secure functions not vulnerable to buffer overflow.
3
If you have to use dangerous functions, make sure that you do boundary checking.
4
Compiler-based canary mechanisms such as StackGuard, ProPolice and the Microsoft Visual Studio /GS flag. Unless this provides automatic bounds checking, it is not a complete solution.
5
Use OS-level preventative functionality. Not a complete solution.
6
Utilize static source code analysis tools to identify potential buffer overflow weaknesses in the software.
Gerçek dünya
MITRE örnek olayları
Örnek olay 1Detay
The most straightforward example is an application that reads in input from the user and stores it in an internal buffer but does not check that the size of the input data is less than or equal to the size of the buffer. If the user enters excessive length data, the buffer may overflow leading to the application crashing, or worse, enabling the user to cause execution of injected code.
Örnek olay 2Detay
Many web servers enforce security in web applications through the use of filter plugins. An example is the SiteMinder plugin used for authentication. An overflow in such a plugin, possibly through a long URL or redirect parameter, can allow an adversary not only to bypass the security checks but also execute arbitrary code on the target web server in the context of the user that runs the web server process.