LinkDoor: A Hidden Attack Surface in the Android Netlink Kernel Modules

  Рет қаралды 1,288

Black Hat

Black Hat

Күн бұрын

Netlink is a socket family designed for inter-process communication (IPC) between the kernel and user-space processes since 1999 with Linux 2.2. With the popularity of Android operating system, it is widely used in the Android kernel modules. Despite its capabilities, Netlink is often overlooked by security researchers due to the strong dominance of ioctl in userspace-kernelspace communication. Its programming complexity compared to ioctl also increases the chance of developers introducing security vulnerabilities. Therefore, Netlink has actually become a hidden attack surface buried deep in the Android ecosystem.
During our research, we found Netlink can be divided into two categories according to its usage, Classic Netlink and Generic Netlink. Each category consists of two message processing flows in the kernel due to its full-duplex characteristic, top-down message parsing and bottom-up message building. Following this idea, we summarized four threat models and analyzed typical vulnerability scenarios for each threat model. Based on these scenarios, we investigated Netlink-related kernel modules from 4 well-known vendors and discovered 30+ security vulnerabilities, and obtained 12 CVEs. Most vulnerabilities have been confirmed, and can lead to serious consequences such as privilege escalation.
In this talk, we will first dive into the Netlink mechanism in the Linux kernel, and then illustrate the security threats of Netlink usage scenarios according to four threat models. Next, we will introduce the analysis, verification and exploitation of Netlink-related vulnerabilities. Finally, we will provide vendors with some security suggestions for using Netlink through vulnerabilities statistics and root cause analysis.
By:
Chao Ma | Security Researcher, Baidu Security
Han Yan | Security Researcher, Baidu Security
Tim Xia | Security Researcher, Baidu Security
Presentation Materials Available:
www.blackhat.c...

Пікірлер
Privacy Detective: Sniffing Out Your Data Leaks for Android
30:04
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН
黑天使只对C罗有感觉#short #angel #clown
00:39
Super Beauty team
Рет қаралды 36 МЛН
Une nouvelle voiture pour Noël 🥹
00:28
Nicocapone
Рет қаралды 9 МЛН
REAL or FAKE? #beatbox #tiktok
01:03
BeatboxJCOP
Рет қаралды 18 МЛН
Keynote - Securing Our Cyberspace Together
1:02:26
Black Hat
Рет қаралды 2,1 М.
Modularization of large Android apps - Lajos Nyéki
31:32
Android Budapest
Рет қаралды 297
Project Zero: Ten Years of 'Make 0-Day Hard'
40:20
Black Hat
Рет қаралды 2,9 М.
Main Stage: Let Me Tell You a Story: Technology and the 4 Vs
26:16
Fireside Chat: Jeff Moss and Ruimin He
53:03
Black Hat
Рет қаралды 544
Practical LLM Security: Takeaways From a Year in the Trenches
37:01
Keynote: Fireside Chat with Moxie Marlinspike
53:30
Black Hat
Рет қаралды 1,2 М.
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН