Sign inSign up

tudinfse/specfuzz_demo

By tudinfse

•Updated over 7 years ago

A small example of how SpecFuzz can be used in practice

Image
0

192

tudinfse/specfuzz_demo repository overview

SpecFuzz is a tool to enable dynamic testing for Bounds Check Bypass vulnerabilities through simulation of conditional branch mispredictions. This repository is a demonstration of how SpecFuzz is used in practice.

To try the demo yourself, start by pulling the Docker container:

$ docker run -it  --name specfuzz_demo tudinfse/specfuzz_demo:latest
# or, to use GDB
$ docker run -it --privileged=true  --name specfuzz_demo tudinfse/specfuzz_demo:latest

This will run a shell with the demo. The container includes 15 Bounds Check Bypass variants written by Paul Kocher⁠

$ ls
access_in_loop                    index_passed_as_pointer      masked_comparison
basic                             inline_if                    memcmp_as_leak
compare_against_last_known        inverted_bits_in_index       separate_safety_value
comparison_as_inline_function     leak_as_inlined_function     shifted_index
comparison_as_noninline_function  leak_as_noninlined_function
index_as_sum                      leak_comparison_result

Each of the variants is build in two versions: a native build (clang_native) and a version with the instrumentation (clang_specfuzz). Both were built with Clang 7.0.1 and on -O3 level of optimization.

$ ls basic
clang_native  clang_specfuzz

As one would expect, the native versions do not expose the vulnerabilities, although each of the examples contains one.

$ cd basic/clang_native
# here, array size is 10
$ ./basic 1  # array index = 1
$ ./basic 1000000  # array index = 1000000, potentially causing a large speculative overflow

The instrumented versions, though, force the application into taking the potentially-mispredicted branches, thus transforming the speculative overflows into conventional ones:

$ cd -
$ cd basic/clang_specfuzz
# here, array size is 10
$ ./basic 1  # array index = 1, no overflow
[SF] Starting
$ ./basic 1000000  # array index = 1000000, potentially causing a large speculative overflow
[SF] Starting
[SF], 11, 0x52998b, 0x529946, 17850944
$ ./basic 2000000  # array index = 2000000
[SF] Starting
[SF], 11, 0x52998b, 0x529946, 18850944 

Here, providing a large value as an array index triggers a buffer overflow during the simulation. When we provide 100000 as an argument, SpecFuzz detects the overflow and reports it in the compressed form [SF], 11, 0x52998b, 0x529946, 17850944, meaning that it detected a speculative bounds violation by the instruction at the address 0x52998b that tried to access the address 17850944 and it was triggered by a misprediction of the branch at the address 0x529946. Moreover, if we provide 2000000 as an argument, SpecFuzz will detect the same overflow but the accessed address will be 18850944, indicating that the attacker may have control over the address. It makes the vulnerability dangerous and, in a real application, it would have to be patched.

Tag summary

Content type

Image

Digest

Size

154.9 MB

Last updated

over 7 years ago

docker pull tudinfse/specfuzz_demo