diff --git a/documentation/source/BootROM_8890/boot_chain.rst b/documentation/source/BootROM_8890/boot_chain.rst new file mode 100644 index 0000000..f281a02 --- /dev/null +++ b/documentation/source/BootROM_8890/boot_chain.rst @@ -0,0 +1,13 @@ +======= +Booting +======= +After exploitation the goal is to fully boot the device. + +debugger +======== +Some other information about the debugger and it's current state. + +ROM +--- + + diff --git a/documentation/source/BootROM_8890/index.rst b/documentation/source/BootROM_8890/index.rst index f9c2514..08498ad 100644 --- a/documentation/source/BootROM_8890/index.rst +++ b/documentation/source/BootROM_8890/index.rst @@ -9,6 +9,8 @@ Protections ----------- There are no stack canaries or guard pages, and no ASLR. Meaning there are almost no protections in place. +Rom is at address 0x0 and is unwritable(Sometimes this is writeable due to MMU caching). + Samsung Firmware ---------------- Samsung releases firmware files for their devices. These files contain the bootloader, modem, and other firmware files. diff --git a/documentation/source/index.rst b/documentation/source/index.rst index 1dc5951..2f09656 100644 --- a/documentation/source/index.rst +++ b/documentation/source/index.rst @@ -12,5 +12,6 @@ Documentation on Samsung devices, currently mainly the Samsung S7. :caption: BootROMs: BootROM_8890/index.rst + BootROM_8890/boot_chain.rst diff --git a/reven/SamsungS7.lock b/reven/SamsungS7.lock index b791c8f..516725f 100644 --- a/reven/SamsungS7.lock +++ b/reven/SamsungS7.lock @@ -1,9 +1,9 @@ #Ghidra Lock File -#Wed Jul 31 20:30:18 CEST 2024 +#Sat Aug 03 17:14:04 CEST 2024 OS\ Name=Linux -OS\ Version=6.5.0-41-generic +OS\ Version=6.5.0-44-generic Username=eljakim Hostname=levith \ Supports\ File\ Channel\ Locking=Channel Lock OS\ Architecture=amd64 -Timestamp=7/31/24, 8\:30 PM +Timestamp=8/3/24, 5\:14 PM diff --git a/reven/SamsungS7.rep/idata/00/00000002.prp b/reven/SamsungS7.rep/idata/00/00000002.prp index e9d40f0..e9cbf94 100644 --- a/reven/SamsungS7.rep/idata/00/00000002.prp +++ b/reven/SamsungS7.rep/idata/00/00000002.prp @@ -2,14 +2,14 @@ - + - + - + - - + + diff --git a/reven/SamsungS7.rep/idata/00/~00000002.db/db.1.gbf b/reven/SamsungS7.rep/idata/00/~00000002.db/db.1.gbf deleted file mode 100644 index d9ff928..0000000 Binary files a/reven/SamsungS7.rep/idata/00/~00000002.db/db.1.gbf and /dev/null differ diff --git a/reven/SamsungS7.rep/idata/~index.bak b/reven/SamsungS7.rep/idata/~index.bak index b1e697f..3dd0917 100644 --- a/reven/SamsungS7.rep/idata/~index.bak +++ b/reven/SamsungS7.rep/idata/~index.bak @@ -1,4 +1,11 @@ VERSION=1 / -NEXT-ID:0 + 00000002:8890_bootrom.bin:7f0119bc3142241939494339 +/mib3 + 00000000:full_boot:7f0118059140616855428589 +/s7 + 00000003:sboot.bin.2.bin:7f011ab837995028720085 + 00000004:sboot.bin.3.bin:7f011872b8163836628792 + 00000005:sboot.bin.4.bin:7f011842b8231996037592 +NEXT-ID:6 MD5:d41d8cd98f00b204e9800998ecf8427e diff --git a/reven/SamsungS7.rep/idata/~index.dat b/reven/SamsungS7.rep/idata/~index.dat index 3d79cef..3dd0917 100644 --- a/reven/SamsungS7.rep/idata/~index.dat +++ b/reven/SamsungS7.rep/idata/~index.dat @@ -3,5 +3,9 @@ VERSION=1 00000002:8890_bootrom.bin:7f0119bc3142241939494339 /mib3 00000000:full_boot:7f0118059140616855428589 -NEXT-ID:3 +/s7 + 00000003:sboot.bin.2.bin:7f011ab837995028720085 + 00000004:sboot.bin.3.bin:7f011872b8163836628792 + 00000005:sboot.bin.4.bin:7f011842b8231996037592 +NEXT-ID:6 MD5:d41d8cd98f00b204e9800998ecf8427e diff --git a/reven/SamsungS7.rep/idata/~journal.bak b/reven/SamsungS7.rep/idata/~journal.bak deleted file mode 100644 index fbe0c2d..0000000 --- a/reven/SamsungS7.rep/idata/~journal.bak +++ /dev/null @@ -1,10 +0,0 @@ -FADD:/NewFolder -FMV:/NewFolder:/mib3 -IADD:00000000:/mib3/fwbl1_a.bin -IDSET:/mib3/fwbl1_a.bin:7f0118059140616855428589 -IMV:/mib3/fwbl1_a.bin:/mib3/full_boot -IADD:00000001:/mib3/8890_bootrom.bin -IDSET:/mib3/8890_bootrom.bin:7f011974d142238523757581 -IADD:00000002:/8890_bootrom.bin -IDSET:/8890_bootrom.bin:7f0119bc3142241939494339 -IDEL:/mib3/8890_bootrom.bin diff --git a/reven/SamsungS7.rep/user/00/~00000001.db/db.1.gbf b/reven/SamsungS7.rep/user/00/~00000001.db/db.1.gbf deleted file mode 100644 index 9620672..0000000 Binary files a/reven/SamsungS7.rep/user/00/~00000001.db/db.1.gbf and /dev/null differ diff --git a/reven/SamsungS7.rep/user/~index.bak b/reven/SamsungS7.rep/user/~index.bak index b1e697f..f0bb25d 100644 --- a/reven/SamsungS7.rep/user/~index.bak +++ b/reven/SamsungS7.rep/user/~index.bak @@ -1,4 +1,8 @@ VERSION=1 / -NEXT-ID:0 + 00000000:udf_7f0118059140616855428589:7f0118d0b142268235940037 + 00000003:udf_7f011872b8163836628792:7f011a9478217161533597 + 00000001:udf_7f0119bc3142241939494339:7f011abb7142807435236045 + 00000002:udf_7f011ab837995028720085:7f0118cdd8148515697603 +NEXT-ID:4 MD5:d41d8cd98f00b204e9800998ecf8427e diff --git a/reven/SamsungS7.rep/user/~index.dat b/reven/SamsungS7.rep/user/~index.dat index 441e2e0..77d0dfb 100644 --- a/reven/SamsungS7.rep/user/~index.dat +++ b/reven/SamsungS7.rep/user/~index.dat @@ -1,5 +1,9 @@ VERSION=1 / 00000000:udf_7f0118059140616855428589:7f0118d0b142268235940037 -NEXT-ID:1 + 00000004:udf_7f011842b8231996037592:7f01190f112184430945139 + 00000003:udf_7f011872b8163836628792:7f011a9478217161533597 + 00000001:udf_7f0119bc3142241939494339:7f011abb7142807435236045 + 00000002:udf_7f011ab837995028720085:7f0118cdd8148515697603 +NEXT-ID:5 MD5:d41d8cd98f00b204e9800998ecf8427e diff --git a/reven/SamsungS7.rep/user/~journal.bak b/reven/SamsungS7.rep/user/~journal.bak index c490adb..ae0f201 100644 --- a/reven/SamsungS7.rep/user/~journal.bak +++ b/reven/SamsungS7.rep/user/~journal.bak @@ -1,2 +1,2 @@ -IADD:00000000:/udf_7f0118059140616855428589 -IDSET:/udf_7f0118059140616855428589:7f0118d0b142268235940037 +IADD:00000004:/udf_7f011842b8231996037592 +IDSET:/udf_7f011842b8231996037592:7f01190f112184430945139 diff --git a/reven/SamsungS7.rep/user/~journal.dat b/reven/SamsungS7.rep/user/~journal.dat deleted file mode 100644 index ca6f18b..0000000 --- a/reven/SamsungS7.rep/user/~journal.dat +++ /dev/null @@ -1,2 +0,0 @@ -IADD:00000001:/udf_7f0119bc3142241939494339 -IDSET:/udf_7f0119bc3142241939494339:7f011abb7142807435236045 diff --git a/source/exploit/.gitignore b/source/exploit/.gitignore index 59393d6..a782873 100644 --- a/source/exploit/.gitignore +++ b/source/exploit/.gitignore @@ -1,2 +1,4 @@ *.elf -*.o \ No newline at end of file +*.o +*.bin +venv/ \ No newline at end of file diff --git a/source/exploit/.vscode/launch.json b/source/exploit/.vscode/launch.json index ed07101..78a455b 100644 --- a/source/exploit/.vscode/launch.json +++ b/source/exploit/.vscode/launch.json @@ -11,6 +11,15 @@ "program": "exploit.py", "console": "integratedTerminal", "args": ["--debug"] + }, + { + "name": "Run chain", + "type": "debugpy", + "request": "launch", + "program": "exploit.py", + "console": "integratedTerminal", + "justMyCode": false, + "args": [] } ] } \ No newline at end of file diff --git a/source/exploit/Readme.md b/source/exploit/Readme.md new file mode 100644 index 0000000..1e2e347 --- /dev/null +++ b/source/exploit/Readme.md @@ -0,0 +1,17 @@ +# Exploit +Python implementation of Frederick's exploit. This gives a bit more insight in the bug. + +## Debugger +The debugger is used for chain loading the next stages. See the documentation folder for more docs + +## Usage +Navigate to stage1 and build it: +``` +export ANDROID_NDK_ROOT=$TOOLCHAINENV/android-ndk-r21_Linux +make +``` +This will build stage1 + +```bash +python3 exploit.py +``` \ No newline at end of file diff --git a/source/exploit/dwc3.elf b/source/exploit/dwc3.elf deleted file mode 100755 index 1531389..0000000 Binary files a/source/exploit/dwc3.elf and /dev/null differ diff --git a/source/exploit/dwc3.o b/source/exploit/dwc3.o deleted file mode 100644 index bf81e16..0000000 Binary files a/source/exploit/dwc3.o and /dev/null differ diff --git a/source/exploit/entry.o b/source/exploit/entry.o deleted file mode 100644 index cfc037f..0000000 Binary files a/source/exploit/entry.o and /dev/null differ diff --git a/source/exploit/exploit.py b/source/exploit/exploit.py index d6cbd79..c8b46ff 100644 --- a/source/exploit/exploit.py +++ b/source/exploit/exploit.py @@ -3,6 +3,9 @@ import struct, sys, usb1, libusb1, ctypes, usb, argparse from keystone import * from capstone import * from ghidra_assistant.utils.utils import * +from ghidra_assistant.concrete_device import * +from ghidra_assistant.utils.debugger.debugger_archs.ga_arm64 import GA_arm64_debugger +from qiling.const import QL_ARCH def p32(x): return struct.pack("
USB Download buffer
0x02021800
0x02070000
stage1 (502 bytes)
0x2021a00
0x206fe00
usb_recv buffer (512 bytes)
0x2069000
Gupje (0x6000 bytes reserved)
Unknown IMEM?
0x2????????
BootROM
0x0
\ No newline at end of file diff --git a/source/exploit/stage1/stage1.c b/source/exploit/stage1/stage1.c new file mode 100644 index 0000000..63f3f12 --- /dev/null +++ b/source/exploit/stage1/stage1.c @@ -0,0 +1,86 @@ +#include + +// Create external function at 0x00006f88 +extern void maybe_usb_setup_read(char endpoint,void *fun,uint32_t target_buffer); +extern void dwc3_ep0_start_trans(char endpoint,uint32_t target_buf, uint32_t len); +extern int usb_event_handler(void); +extern uint32_t get_endpoint_recv_buffer(char endpoint); +extern void sleep(int endpoint,uint32_t timeout); +extern void usb_send(uint32_t address,uint32_t size); +extern void rom_send(); + +#define recv_buffer 0x206fe00 //0x02021800 + 0x3000 +#define data_received 0x206fd00 + +void recv_data_cb(uint32_t endpoint, uint32_t len){ + char *dest_buf = (char *)recv_buffer; + volatile void *dref = (void *)data_received; + + void *rbuf = get_endpoint_recv_buffer(endpoint); + for(int i= 0; i < len; i++){ + dest_buf[i] = *(char *)(void *)((int)rbuf + i); + } + *(uint8_t *)dref = 1; // Mark as ready +} + +void recv_data(uint32_t address, uint32_t size){ + // + volatile void *dref = (void *)data_received; + *(uint8_t *)dref = 0; + + maybe_usb_setup_read(2, recv_data_cb, 0x200); + uint32_t rbuf = get_endpoint_recv_buffer(2); + dwc3_ep0_start_trans(2, rbuf, 0x200); + while(1){ + usb_event_handler(); + if(*(uint8_t *)dref == 1){ + break; + } + } + // Copy to destination location + char *dest_buf = (char *)address; + for(int i= 0; i < size; i++){ + dest_buf[i] = *(char *)(void *)((int)recv_buffer + i); + } +} + +// void send_data_cb(uint32_t endpoint, uint32_t len){ +// // Tell event handler that the data was received +// volatile void *dref = (void *)data_received; +// *(uint8_t *)dref = 1; // Mark as ready +// } + +// void send_data(uint32_t address, uint32_t size){ +// volatile void *dref = (void *)data_received; +// *(uint8_t *)dref = 0; +// maybe_usb_setup_read(0x1, send_data_cb, size); +// // uint32_t rbuf = get_endpoint_recv_buffer(1); +// dwc3_ep0_start_trans(1, address, size); +// while(1){ +// usb_event_handler(); +// if(*(uint8_t *)dref == 1){ +// break; +// } +// } +// } +#define debugger_location 0x2069000 + +int main() { + // First payload is 0x2000 in size + int block_sz = 0x200; + int to_recv = 0x2000; + for(int block = 0; block < to_recv; block+=block_sz){ + recv_data(0x2069000 + block, block_sz); + } + + // Create function at debugger_location + void (*custom_func)() = (void*)0x2069000; //mem_off; + custom_func(); + + // uint32_t count = 0; + // while(1){ + // // recv_data(); + // // send_data(recv_buffer, 0x200); + // // send_data("GiAs", 4); + // } +} \ No newline at end of file diff --git a/source/exploit/symbols.txt b/source/exploit/stage1/symbols.txt similarity index 100% rename from source/exploit/symbols.txt rename to source/exploit/stage1/symbols.txt diff --git a/source/exploit/test_dwc3.c b/source/exploit/test_dwc3.c deleted file mode 100644 index b50ba48..0000000 --- a/source/exploit/test_dwc3.c +++ /dev/null @@ -1,72 +0,0 @@ -#include - -// Create external function at 0x00006f88 -extern void maybe_usb_setup_read(char endpoint,void *fun,uint32_t target_buffer); -extern void dwc3_ep0_start_trans(char endpoint,uint32_t target_buf, uint32_t len); -extern int usb_event_handler(void); -extern uint32_t get_endpoint_recv_buffer(char endpoint); -extern void sleep(int endpoint,uint32_t timeout); -extern void usb_send(uint32_t address,uint32_t size); -extern void rom_send(); - -#define recv_buffer 0x02021800 + 0x3000 -#define data_received 0x02021800 + 0x2004 - -void recv_data_cb(uint32_t endpoint, uint32_t len){ - char *dest_buf = (char *)recv_buffer; - volatile void *dref = (void *)data_received; - - void *rbuf = get_endpoint_recv_buffer(endpoint); - for(int i= 0; i < len; i++){ - dest_buf[i] = *(char *)(void *)((int)rbuf + i); - } - *(uint8_t *)dref = 1; // Mark as ready -} - -void recv_data(){ - // Set data_received to 0 - // uint32_t *r = (uint32_t *) data_received; - // r = 0; - volatile void *dref = (void *)data_received; - *(uint8_t *)dref = 0; - - maybe_usb_setup_read(2, recv_data_cb, 0x200); - uint32_t rbuf = get_endpoint_recv_buffer(2); - dwc3_ep0_start_trans(2, rbuf, 0x200); - while(1){ - usb_event_handler(); - if(*(uint8_t *)dref == 1){ - break; - } - } -} - -void send_data_cb(uint32_t endpoint, uint32_t len){ - // Tell event handler that the data was received - volatile void *dref = (void *)data_received; - *(uint8_t *)dref = 1; // Mark as ready -} - -void send_data(uint32_t address, uint32_t size){ - volatile void *dref = (void *)data_received; - *(uint8_t *)dref = 0; - maybe_usb_setup_read(0x1, send_data_cb, 0x200); - // uint32_t rbuf = get_endpoint_recv_buffer(1); - dwc3_ep0_start_trans(1, address, 0x200); - while(1){ - usb_event_handler(); - if(*(uint8_t *)dref == 1){ - break; - } - } -} - - -int main() { - - uint32_t count = 0; - while(1){ - recv_data(); - send_data(recv_buffer, 0x200); - } -} \ No newline at end of file