目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2022-3786 PoC — OpenSSL 安全漏洞

来源
关联漏洞
标题: OpenSSL 安全漏洞 (CVE-2022-3786)
Description:OpenSSL是OpenSSL团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL 3.0.0 到 3.0.6版本存在安全漏洞,该漏洞源于在 X.509 证书验证中可以触发缓冲区溢出,特别是在名称约束检查中,攻击者利用该漏洞可以导致服务崩溃(导致拒绝服务)。
Description
Finding CVE-2022-3786 (openssl) with Mayhem
介绍
# Fuzzing OpenSSL

This repository has a companion blog post titled "Finding CVE-2022-3786 (openssl) with Mayhem" at https://www.seandeaton.com.

## tl;dr

All of this is taken care of for you with the included Dockerfile (also on DockerHub). You can run it like so:

```shell
# Build the container
docker build --tag openssl-cve-2022-3768 .
# Or if you just want to pull down the existing one:
TODO
# Ensure that you're in this project's root directory (ie you can see ./output/)
# Mount the ./input/ directory to the containers /input. This is for fuzz input.
# This is Linux specific, Windows I think has %CD% in lieu of $(pwd)?
docker run --interactive --tty --volume $(pwd)/input:/input
```

The entrypoint of the container is to just run `afl` so you can get started
fuzzing immediately. To override this behavior, append `/bin/bash` to the end
of the `docker run` line.

## Getting a Vulnerable Version

The last commit that includes the vulnerability is commit SHA `3b421ebc64c7b52f1b9feb3812bdc7781c784332` from November 1st, 2022. It was fixed in commit SHA `680e65b94c916af259bfdc2e25f1ab6e0c7a97d6`. We can get the vulnerable version easily with `git`:

```shell
# Clone the repository.
git clone git://git.openssl.org/openssl.git
# Change into the working directory.
cd openssl
# Detach HEAD from origin to examine the code as it was when it was vulnerable.
git checkout 3b421ebc64c7b52f1b9feb3812bdc7781c784332
```

## Compiling

For compilation, we use AFL's gcc compiler (because I kept getting undefined
references with `clang`). Because of the small buffer overflow
offset, we also want to use address sanitization (ASAN), enabled with AFL's
environment variable `AFL_USE_ASAN`. Given ASAN's use of large amounts of
memory, we also need to restrict the address space which we can do by compiling
the program for a 32-bit architecture. More detail [here][afl-asan].

OpenSSL's configuration for 32-bit takes in the flags `-m32` and
`linux-generic32`. The `compile.sh` script does this for you.

```shell
# Configuration
AFL_USE_ASAN=1 CC=afl-gcc-fast CXX=afl-g++-fast ./Configure -m32 linux-generic32
# Make
AFL_USE_ASAN=1 CC=afl-gcc-fast CXX=afl-g++-fast CFLAGS="-m32" CXXFLAGS="-m32" make
```

This could take awhile given your system's resources. After compilation, we need
to compile our harness. A Makefile is given.

```shell
# Compile the harness.
$ make harness
# Run the harness.
$ ./harness input/seed0.txt
ossl_a2ulabel returned: 1
```

And there you go, you can get started fuzzing the `ossl_a2ulabel` in `openssl`.
With AFL the command looks something like the following (or just use the
included `run.sh` script).

```shell
afl-fuzz -i /input -o /output /harness/harness @@
```

[afl-asan]: https://afl-1.readthedocs.io/en/latest/notes_for_asan.html
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →