COMMON ATTACK PATTERN ENUMERATION AND CLASSIFICATIONMITRE canlı kaydı

CAPEC-45

Buffer Overflow via Symbolic Links

This type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulate a symbolic link file such that its contents result in out of bounds data. When the target software processes the symbolic link file, it could potentially overflow internal buffers with insufficient bounds checking.

Soyutlama

Detailed

Tipik ciddiyet

High

Saldırı ihtimali

High

Saldırıyı anla

Bu saldırı kalıbı nedir?

This type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulate a symbolic link file such that its contents result in out of bounds data. When the target software processes the symbolic link file, it could potentially overflow internal buffers with insufficient bounds checking.

Uygulama akışı

Saldırı adım adım nasıl ilerler?

1

Explore

Identify target application

The adversary identifies a target application or program that might load in certain files to memory.
2

Experiment

Find injection vector

The adversary identifies an injection vector to deliver the excessive content to the targeted application's buffer.

Kullanılan teknikler

  • The adversary creates or modifies a symbolic link pointing to those files which contain an excessive amount of data. If creating a symbolic link to one of those files causes different behavior in the application, then an injection vector has been identified.

Craft overflow file content

The adversary crafts the content to be injected. If the intent is to simply cause the software to crash, the content need only consist of an excessive quantity of random data. If the intent is to leverage the overflow for execution of arbitrary code, the adversary crafts the payload in such a way that the overwritten return address is replaced with one of the adversary's choosing.

Kullanılan teknikler

  • Create malicious shellcode that will execute when the program execution is returned to it.
  • Use a NOP-sled in the overflow content to more easily "slide" into the malicious code. This is done so that the exact return address need not be correct, only in the range of all of the NOPs
3

Exploit

Overflow the buffer

Using the specially crafted file content, the adversary creates a symbolic link from the identified resource to the malicious file, causing a targeted buffer overflow attack.

Gereksinimler

Saldırının gerçekleşmesi için ne gerekir?

Ön koşullar

  • The adversary can create symbolic link on the target host.
  • The target host does not perform correct boundary checking while consuming data from a resources.

Gerekli beceri

  • Low: An adversary can simply overflow a buffer by inserting a long string into an adversary-modifiable injection vector. The result can be a DoS.
  • High: Exploiting a buffer overflow to inject malicious code into the stack of a software system or even the heap can require a higher skill level.

Gerekli kaynak

MITRE kaydında belirtilmemiş.

Tespit

Saldırının göstergeleri nelerdir?

An adversary creating or modifying Symbolic links is a potential signal of attack in progress.
An adversary deleting temporary files can also be a sign that the adversary is trying to replace legitimate resources with malicious ones.

Etki

Başarılı saldırı neye yol açar?

Unreliable Execution

Etkilenen alanlar: Availability

Execute Unauthorized Commands

Etkilenen alanlar: Confidentiality, Integrity, Availability

Read Data

Etkilenen alanlar: Confidentiality

Modify Data

Etkilenen alanlar: Integrity

Savunma

Nasıl önlenir ve etkisi azaltılır?

1
Pay attention to the fact that the resource you read from can be a replaced by a Symbolic link. You can do a Symlink check before reading the file and decide that this is not a legitimate way of accessing the resource.
2
Because Symlink can be modified by an adversary, make sure that the ones you read are located in protected directories.
3
Pay attention to the resource pointed to by your symlink links (See attack pattern named "Forced Symlink race"), they can be replaced by malicious resources.
4
Always check the size of the input data before copying to a buffer.
5
Use a language or compiler that performs automatic bounds checking.
6
Use an abstraction library to abstract away risky APIs. Not a complete solution.
7
Compiler-based canary mechanisms such as StackGuard, ProPolice and the Microsoft Visual Studio /GS flag. Unless this provides automatic bounds checking, it is not a complete solution.
8
Use OS-level preventative functionality. Not a complete solution.

Gerçek dünya

MITRE örnek olayları

Örnek olay 1Detay
The EFTP server has a buffer overflow that can be exploited if an adversary uploads a .lnk (link) file that contains more than 1,744 bytes. This is a classic example of an indirect buffer overflow. First the adversary uploads some content (the link file) and then the adversary causes the client consuming the data to be exploited. In this example, the ls command is exploited to compromise the server software.
CAPEC-45: Buffer Overflow via Symbolic Links — DayBreach Saldırı Sözlüğü · DayBreach