软件安全Attack Lab第5阶段ROP攻击段错误问题求助
Hey there, let's tackle your questions first, then dive into why your ROP chain is causing a segmentation fault.
Your Core Questions Explained
1. Why do we need to calculate the sum of %rsp and an address offset?
With ASLR (Address Space Layout Randomization) enabled, the stack's base address changes every time the program runs. Your cookie string is stored directly on the stack, so we can't hardcode its address—we need a dynamic way to locate it.
%rsp holds the current top of the stack when your ROP gadgets start executing. By adding the fixed offset between %rsp (at that moment) and the cookie string's position on the stack, we can reliably compute the string's actual address, regardless of ASLR's randomization.
2. Why pop the offset into %rax first, then use it to get the cookie string address?
Looking at your intended ROP logic, you're trying to use the lea (%rdi, %rsi, 1), %rax gadget to perform an addition: rdi + rsi = cookie string address.
Here's the flow:
- First, we save
%rspinto%rdi(so%rdiholds the starting stack address) - We pop the offset into
%raxbecausepopis one of the easiest ways to load a constant into a register with ROP - Then we move that offset from
%raxto%rsi(since theleagadget uses%rsias the source register for the addition) - Finally, the
leagadget computes the sum, giving us the cookie string's address in%rax
Why Your ROP Chain Is Causing a Segmentation Fault
The biggest issue is that you've misidentified almost all your gadgets. You're confusing instruction bytes with immediate data values in other instructions—these aren't valid executable gadgets for your intended operations. Let's break down the critical mistakes:
1. Invalid Gadget for mov %rsp, %rax
Your step 1 gadget:
401ae6: b8 27 48 89 e0 mov $0xe0894827,%eax;401aeb: c3
This doesn't move %rsp into %rax—it loads the immediate value 0xe0894827 into %eax. The bytes 48 89 e0 are part of the immediate data, not an executable instruction. You need to find a gadget where the executable bytes are 48 89 e0 c3 (the actual mov %rsp, %rax instruction followed by a ret).
2. Invalid Gadget for mov %rax, %rdi
Your step 2 gadget:
401a2d: 8d 87 48 89 c7 90 lea -0x6f3876b8(%rdi),%eax;401a33: c3
This executes a lea instruction, not mov %rax, %rdi. The bytes 48 89 c7 are part of the offset for the lea operation, not a standalone mov instruction. You need a gadget with executable bytes 48 89 c7 c3.
3. Invalid Gadgets for Register Moves (Steps 5-7)
For steps 5-7, you're trying to move values between registers (movl %eax, %edx, movl %edx, %ecx, movl %ecx, %esi), but your gadgets are all storing immediate values to memory (e.g., movl $0xc390c289,(%rdi)). Again, you're picking bytes from immediate data instead of valid executable instructions.
Fixing Your ROP Chain
Here's a corrected approach for your ROP sequence:
- Gadget:
48 89 e0 c3(find where this byte sequence exists in the binary) →mov %rsp, %rax; ret - Gadget:
48 89 c7 c3→mov %rax, %rdi; ret(saves stack pointer to%rdi) - Gadget:
58 c3→pop %rax; ret(loads your offset0x48into%rax) - Offset:
0x48(your calculated offset, correct if the string is 72 bytes from%rspat step 1) - Gadget:
48 89 c6 c3→mov %rax, %rsi; ret(moves offset to%rsi) - Gadget:
48 8d 04 37 c3→lea (%rdi, %rsi, 1), %rax; ret(calculates cookie string address) - Gadget:
48 89 c7 c3→mov %rax, %rdi; ret(puts string address into%rdifortouch3) - Address:
touch3address (you confirmed this is correct) - Cookie String: Your null-terminated cookie string (confirmed correct)
To fix your current chain, re-scan the binary for valid gadgets that match the exact instruction sequences you need—don't confuse immediate data bytes with executable instructions.
内容的提问来源于stack exchange,提问作者user7151309

