<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ASLR on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/aslr/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 10 May 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/aslr/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Reaper2</title><link>https://wearethebug.dev/posts/vl-reaper2/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper2/</guid><description>ReaperTwo is an Insane Windows machine that involves both browser and kernel exploitation. The attack chain begins with enumeration of exposed services and access to an SMB share containing development artifacts. A vulnerable web application leveraging the V8 JavaScript engine allows for arbitrary JavaScript execution, which is escalated to remote code execution through a type confusion vulnerability in Harmony Set methods, combined with WebAssembly-based shellcode execution. After gaining an initial foothold as a low-privileged user, privilege escalation is achieved by exploiting a vulnerable kernel driver that exposes a function pointer execution primitive. The exploit bypasses modern protections such as kASLR, DEP, and SMEP by leaking kernel addresses via MSRs, performing a stack pivot, and constructing a ROP chain to modify Page Table Entries (PTEs). Finally, custom kernel shellcode is executed to steal a SYSTEM token, resulting in full system compromise.</description></item><item><title>VULNLAB: Rainbow2</title><link>https://wearethebug.dev/posts/vl-rainbow2/</link><pubDate>Mon, 06 Jun 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow2/</guid><description>Rainbow2 is a Hard Windows machine centered around exploit development for a custom network file-sharing service. Initial enumeration reveals anonymous FTP access and an unknown service listening on TCP port 2121. The FTP share exposes the vulnerable service binary, a developer README, and a copy of SysWOW64\kernel32.dll. The README confirms that the service was rebuilt with ASLR, DEP, and GS enabled. Static and dynamic analysis then shows that the service is still vulnerable to a format string issue and a stack-based overflow that overwrites the SEH chain. The format string leak provides a reliable ASLR bypass by disclosing a pointer inside filesrv.exe; the SEH overwrite provides control of the exception handler; and a ROP chain calls VirtualAlloc to bypass DEP. Privilege escalation is achieved by abusing SeDebugPrivilege to migrate into a SYSTEM process.</description></item></channel></rss>