Sneaky Bit Flipper | Azeria Labs creator | Author of “Arm Assembly Internals & Reverse Engineering”
Posts
GCC’s stack protection feature (aka canary) is an exploit mitigation to prevent buffer overflows from overwriting saved registers on the stack to take control over the program flow. It makes exploitation much harder. You often need an additional bug to bypass this mitigation.
The issue: When targeting AArch64, this mitigation didn’t protect saved registers from overflows in C99-style dynamically allocated local variables and alloca() objects.
Time for an Arm-twist! CVE-2023-4039
Tom Hebb (Meta red team) and I discovered an 0day in GCC (for AArch64 targets) during my Arm exploitation training.
It renders stack canaries against overflows of dynamically-sized variables useless.
https://developer.arm.com/Arm%20Security%20Center/GCC%20Stack%20Protector%20Vulnerability%20AArch64
I’m doing two book signing sessions in collaboration with Patrick Wardle at Black Hat and Defcon this year! 🥳
Black Hat:
Thursday 8/10 - 12:15pm:
BH Bookstore - Breakers Registration 2
Defcon:
Saturday 8/12 - 11:00am
Caesar’s - Alliance Ballroom - Room 321
My own book copy arrived today!
Words can’t express how it feels like to hold 3 years of work in your hands…
My new book "Arm Assembly Internals & Reverse Engineering" is up for pre-order!
Save the date for the official launch: May 9th.
Can't wait for you to dive into the world of Arm Assembly!
Check out the official book page for more info:
https://arm-assembly.com
@securingdev@infosec.exchange @0xamit@infosec.exchange @malwaretech@infosec.exchange tbf I mainly use Debian, especially for Arm distros. I haven’t use Kali since I was a junior Pentester. I would recommend a clean system, then carefully install what you really need as you go. Especially for exploit dev, you’d need debuggers or GDB wrappers (e.g. GEF or Peda) and other tools you don’t necessarily find on Kali. For malware analysis, it depends what type of malware you’re analyzing