HNHacker News
TopNewBestAskShowJobs

qwertyoruiop

97 karma · joined November 30, 2012

submissionscomments
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
I have asked on Twitter if anyone could sign it for me. For some reason neither of the two people who tried to do so were able to sign it. No idea why. kexts were signed but they kept getting rejected for some reason.
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
iOS is vulnerable too as far as the vulnerability is concerned. It is not directly exploitable on iOS, however having a NULL task_t still does give you some abilities, even if not (directly?) SVC code exec.
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
while I agree with you on the security benefits of a full microkernel, to be entirely honest, if you had access to just IOKit you could easily use a network card or an hard drive controller to get a physical memory write-what-where, which in turn would allow you to gain access to anything, plus the microkernel performance issues of e.g. having to context switch on interrupts.
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
well, this bug is a null pointer deference. smap is like -no_shared_cr3, but without the performance loss.
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
Then you should not install them on a machine with confidential data at all, source or binary. It's that simple!
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
for the record: "At 0x20 I place a POP RAX;RET gadget" should be "At 0x18 I place a POP RAX;RET gadget".
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
for the record: i had no idea yesterday was saturday at the time I dropped the code.
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
I did not have the patch ready when the exploit was published, that's the only reason why. I had my reasons to publish the exploit in public yesterday, but all I can say is "no comment".

Just for the record: I did inform Apple beforehand. Not so much before, but before.

I do not consider this to be their fault in any way as someone in this thread seems to be implying. Again, I had my reasons to drop such a thing publicly. I've had this for months, and I did not intend on disclosing at all. Proof of my "for months" assertion: https://www.youtube.com/watch?v=8arPid8GtFk

> As a bare minimum Apple needs a few hours to analyze the bug

Again, for the record: Apple has full details of the underlying bug. They won't even need to check my github at all.

qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
> and the author made no effort at all to reduce the impact

http://github.com/kpwn/NULLGuard

qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
You are not vulnerable since you have SMAP!
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
If the heap info leak fails, I bail out cleanly. If the kASLR leak fails, it is usually because instead of hitting a vm_map_copy (the intended structure I need to corrupt), something completely unrelated is hit instead. If it happens to hit something different than expected, that's undefined behaviour usually ending up in a panic.
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
1) I cannot really discuss specifics, but this particular bug would have been hard to find via a traditional IOKit fuzz, since it requires an invalid 'task' port passed over to IOServiceOpen. Most fuzzers use mach_task_self for that, and fuzz method calls/traps/properties/etc.

2) When IOServiceRelease is called, vtable+0x20 is called. the vtable pointer is controlled, at +0x20 I place a stack pivot, which sets RSP = RAX and pops 3 times. At 0x20 I place a POP RAX;RET gadget to let the chain begin after 0x28. Payload then locates the credentials structure, sets UID to 0 by bzero()ing, cleans up the memory corruption, decreases the task count for current user and increases task count for root. It then unlocks locks held by IOAudioEngine to prevent your audio from freezing up, and then returns to the userland context.

qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
'sudo nvram boot-args=-no_shared_cr3' will do the trick.

The flag essentially prevents kernel from accessing userland memory unless special routines are used. Since the bug is a NULL pointer deference (which requires a read to userland memory in order to be exploited), exploitation becomes impossible. Due to this flag, however, your kernel will have to context switch every time a system call is done, which does have a noticeable performance impact. I will be releasing a KEXT to fix the bug soon.

qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
Yes, it is.
qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
add -no_shared_cr3 to your boot-args.

it will have an hefty performance penalty, but if you value security over performance, it'll also protect you against a lot of (even 0day!) exploits.

qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
> tpwn has been tested from 10.9 to 10.10.5, but of course, your mileage may vary.

10.10.3 was actually the first version it was tested on.

qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
There is no weakness in address randomization I relied on for exploitation.

It relies on two distinct bugs, an info-leak to obtain a pointer to an allocation in the kalloc.1024 zone and a memory corruption primitive (deriving from a NULL pointer dfr. in IOKit) allowing me to OR 0x10 anywhere in kernel memory.

To break kASLR I corrupt the size of a vm_map_copy struct, which allows me to read the adjacent allocation to the struct, which is a C++ object. First 8 bytes of said C++ object is a pointer to the vtable, which resides in __TEXT of some kernel extension. Since I can calculate the unslid address from userland without any issue, by subtracting what gets leaked with what gets calculated you get to know the kASLR slide.

Just to clarify: The code execution part has 100% reliability rate. The kASLR leaking part does have some chance in it, however empirical evidence indicates that the failure rate is extremely low.

qwertyoruiop··on OS X 10.10.5 kernel local privilege escalation
Interesting. I am on 10.10.4 myself, and that's the OS I tested it on.

tpwn has been tested from 10.9 to 10.10.5, but of course, your mileage may vary. the KASLR leak part is not 100% reliable, unlike the actual code execution which is. I'd be interested in panic logs to sort the issue out, if you could share.

qwertyoruiop··on Tor exit node operator raided in Austria
> A TB of traffic will cost at least around €2-3 from most european (and other) ISPs with VPS

The average bandwidth price I got from all the ISPs I used in the past was ~1 dollar/megabit. The ISPs I used for my Tor relays were ISPs I was using already for bandwidth-intensive HTTP hosting, so I already had quite a few deals for dirt cheap bandwidth.

I've been paying ~600€ per box (1Gbit, of which I was using at least 60% 24/7, getting to 100% during day hours).

> you basically claim to have enough spare change lying around at the age of 15 to pay €2000-3000/month just for Tor traffic because you're an idealist

Yep. I got it mostly by selling iOS Tweaks on Cydia Store, private consulting with a few companies, freelancing, and sysadmining.

> and after buying all the stuff a 15 year old normally buys first? ;-)

The only thing apart from my tech equipment and servers that I'm interesting in buying is weed anyway.

> (and btw., WW was not running the ISP, he wrote somewhere in this thread that he is just a normal employee)

Thanks for clarifying that he was not running the ISP. I misread it, probably.

qwertyoruiop··on Tor exit node operator raided in Austria
I'm a 15 year old 'kid` that has been pushing 30TB/day traffic thru a few Tor exits for months just fine, because I truly believe in freedom of speech.

You know, money isn't that hard to get. For me, a few weeks of coding got me a few thousands of euros. He was running an ISP apparently, and selling VPSs. I've been sysadmining a few boxes for a few VPS hosting companies and got enough money to run a few Tor exits pushing over 2Gbps for months.

(Also, I think that it's hilarious that me having my 15-year-old girlfriend pics is considered illegal, thanks to CP laws. )

I truly believe in this: http://datalove.me/