A small example of how SpecFuzz can be used in practice
192
SpecFuzz is a tool to enable dynamic testing for Bounds Check Bypass vulnerabilities through simulation of conditional branch mispredictions. This repository is a demonstration of how SpecFuzz is used in practice.
To try the demo yourself, start by pulling the Docker container:
$ docker run -it --name specfuzz_demo tudinfse/specfuzz_demo:latest
# or, to use GDB
$ docker run -it --privileged=true --name specfuzz_demo tudinfse/specfuzz_demo:latest
This will run a shell with the demo. The container includes 15 Bounds Check Bypass variants written by Paul Kocher
$ ls
access_in_loop index_passed_as_pointer masked_comparison
basic inline_if memcmp_as_leak
compare_against_last_known inverted_bits_in_index separate_safety_value
comparison_as_inline_function leak_as_inlined_function shifted_index
comparison_as_noninline_function leak_as_noninlined_function
index_as_sum leak_comparison_result
Each of the variants is build in two versions: a native build (clang_native) and a version with the instrumentation (clang_specfuzz). Both were built with Clang 7.0.1 and on -O3 level of optimization.
$ ls basic
clang_native clang_specfuzz
As one would expect, the native versions do not expose the vulnerabilities, although each of the examples contains one.
$ cd basic/clang_native
# here, array size is 10
$ ./basic 1 # array index = 1
$ ./basic 1000000 # array index = 1000000, potentially causing a large speculative overflow
The instrumented versions, though, force the application into taking the potentially-mispredicted branches, thus transforming the speculative overflows into conventional ones:
$ cd -
$ cd basic/clang_specfuzz
# here, array size is 10
$ ./basic 1 # array index = 1, no overflow
[SF] Starting
$ ./basic 1000000 # array index = 1000000, potentially causing a large speculative overflow
[SF] Starting
[SF], 11, 0x52998b, 0x529946, 17850944
$ ./basic 2000000 # array index = 2000000
[SF] Starting
[SF], 11, 0x52998b, 0x529946, 18850944
Here, providing a large value as an array index triggers a buffer overflow during the simulation. When we provide 100000 as an argument, SpecFuzz detects the overflow and reports it in the compressed form [SF], 11, 0x52998b, 0x529946, 17850944, meaning that it detected a speculative bounds violation by the instruction at the address 0x52998b that tried to access the address 17850944 and it was triggered by a misprediction of the branch at the address 0x529946. Moreover, if we provide 2000000 as an argument, SpecFuzz will detect the same overflow but the accessed address will be 18850944, indicating that the attacker may have control over the address. It makes the vulnerability dangerous and, in a real application, it would have to be patched.
Content type
Image
Digest
Size
154.9 MB
Last updated
over 7 years ago
docker pull tudinfse/specfuzz_demo