1*9712c20fSFrederick Mayle // Copyright 2010 Google LLC
2*9712c20fSFrederick Mayle //
3*9712c20fSFrederick Mayle // Redistribution and use in source and binary forms, with or without
4*9712c20fSFrederick Mayle // modification, are permitted provided that the following conditions are
5*9712c20fSFrederick Mayle // met:
6*9712c20fSFrederick Mayle //
7*9712c20fSFrederick Mayle // * Redistributions of source code must retain the above copyright
8*9712c20fSFrederick Mayle // notice, this list of conditions and the following disclaimer.
9*9712c20fSFrederick Mayle // * Redistributions in binary form must reproduce the above
10*9712c20fSFrederick Mayle // copyright notice, this list of conditions and the following disclaimer
11*9712c20fSFrederick Mayle // in the documentation and/or other materials provided with the
12*9712c20fSFrederick Mayle // distribution.
13*9712c20fSFrederick Mayle // * Neither the name of Google LLC nor the names of its
14*9712c20fSFrederick Mayle // contributors may be used to endorse or promote products derived from
15*9712c20fSFrederick Mayle // this software without specific prior written permission.
16*9712c20fSFrederick Mayle //
17*9712c20fSFrederick Mayle // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
18*9712c20fSFrederick Mayle // "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
19*9712c20fSFrederick Mayle // LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
20*9712c20fSFrederick Mayle // A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
21*9712c20fSFrederick Mayle // OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
22*9712c20fSFrederick Mayle // SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
23*9712c20fSFrederick Mayle // LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
24*9712c20fSFrederick Mayle // DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
25*9712c20fSFrederick Mayle // THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26*9712c20fSFrederick Mayle // (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
27*9712c20fSFrederick Mayle // OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28*9712c20fSFrederick Mayle
29*9712c20fSFrederick Mayle // exploitability_engine.cc: Generic exploitability engine.
30*9712c20fSFrederick Mayle //
31*9712c20fSFrederick Mayle // See exploitable_engine.h for documentation.
32*9712c20fSFrederick Mayle //
33*9712c20fSFrederick Mayle // Author: Cris Neckar
34*9712c20fSFrederick Mayle
35*9712c20fSFrederick Mayle
36*9712c20fSFrederick Mayle #ifdef HAVE_CONFIG_H
37*9712c20fSFrederick Mayle #include <config.h> // Must come first
38*9712c20fSFrederick Mayle #endif
39*9712c20fSFrederick Mayle
40*9712c20fSFrederick Mayle #include <cassert>
41*9712c20fSFrederick Mayle
42*9712c20fSFrederick Mayle #include "common/scoped_ptr.h"
43*9712c20fSFrederick Mayle #include "google_breakpad/processor/exploitability.h"
44*9712c20fSFrederick Mayle #include "google_breakpad/processor/minidump.h"
45*9712c20fSFrederick Mayle #include "google_breakpad/processor/process_state.h"
46*9712c20fSFrederick Mayle #include "processor/exploitability_linux.h"
47*9712c20fSFrederick Mayle #include "processor/exploitability_win.h"
48*9712c20fSFrederick Mayle #include "processor/logging.h"
49*9712c20fSFrederick Mayle
50*9712c20fSFrederick Mayle namespace google_breakpad {
51*9712c20fSFrederick Mayle
Exploitability(Minidump * dump,ProcessState * process_state)52*9712c20fSFrederick Mayle Exploitability::Exploitability(Minidump *dump,
53*9712c20fSFrederick Mayle ProcessState *process_state)
54*9712c20fSFrederick Mayle : dump_(dump),
55*9712c20fSFrederick Mayle process_state_(process_state) {}
56*9712c20fSFrederick Mayle
CheckExploitability()57*9712c20fSFrederick Mayle ExploitabilityRating Exploitability::CheckExploitability() {
58*9712c20fSFrederick Mayle return CheckPlatformExploitability();
59*9712c20fSFrederick Mayle }
60*9712c20fSFrederick Mayle
ExploitabilityForPlatform(Minidump * dump,ProcessState * process_state)61*9712c20fSFrederick Mayle Exploitability *Exploitability::ExploitabilityForPlatform(
62*9712c20fSFrederick Mayle Minidump *dump,
63*9712c20fSFrederick Mayle ProcessState *process_state) {
64*9712c20fSFrederick Mayle return ExploitabilityForPlatform(dump, process_state, false);
65*9712c20fSFrederick Mayle }
66*9712c20fSFrederick Mayle
ExploitabilityForPlatform(Minidump * dump,ProcessState * process_state,bool enable_objdump)67*9712c20fSFrederick Mayle Exploitability *Exploitability::ExploitabilityForPlatform(
68*9712c20fSFrederick Mayle Minidump *dump,
69*9712c20fSFrederick Mayle ProcessState *process_state,
70*9712c20fSFrederick Mayle bool enable_objdump) {
71*9712c20fSFrederick Mayle Exploitability *platform_exploitability = NULL;
72*9712c20fSFrederick Mayle MinidumpSystemInfo *minidump_system_info = dump->GetSystemInfo();
73*9712c20fSFrederick Mayle if (!minidump_system_info)
74*9712c20fSFrederick Mayle return NULL;
75*9712c20fSFrederick Mayle
76*9712c20fSFrederick Mayle const MDRawSystemInfo *raw_system_info =
77*9712c20fSFrederick Mayle minidump_system_info->system_info();
78*9712c20fSFrederick Mayle if (!raw_system_info)
79*9712c20fSFrederick Mayle return NULL;
80*9712c20fSFrederick Mayle
81*9712c20fSFrederick Mayle switch (raw_system_info->platform_id) {
82*9712c20fSFrederick Mayle case MD_OS_WIN32_NT:
83*9712c20fSFrederick Mayle case MD_OS_WIN32_WINDOWS: {
84*9712c20fSFrederick Mayle platform_exploitability = new ExploitabilityWin(dump, process_state);
85*9712c20fSFrederick Mayle break;
86*9712c20fSFrederick Mayle }
87*9712c20fSFrederick Mayle case MD_OS_LINUX: {
88*9712c20fSFrederick Mayle platform_exploitability = new ExploitabilityLinux(dump,
89*9712c20fSFrederick Mayle process_state,
90*9712c20fSFrederick Mayle enable_objdump);
91*9712c20fSFrederick Mayle break;
92*9712c20fSFrederick Mayle }
93*9712c20fSFrederick Mayle case MD_OS_MAC_OS_X:
94*9712c20fSFrederick Mayle case MD_OS_IOS:
95*9712c20fSFrederick Mayle case MD_OS_UNIX:
96*9712c20fSFrederick Mayle case MD_OS_SOLARIS:
97*9712c20fSFrederick Mayle case MD_OS_ANDROID:
98*9712c20fSFrederick Mayle case MD_OS_PS3:
99*9712c20fSFrederick Mayle case MD_OS_FUCHSIA:
100*9712c20fSFrederick Mayle default: {
101*9712c20fSFrederick Mayle platform_exploitability = NULL;
102*9712c20fSFrederick Mayle break;
103*9712c20fSFrederick Mayle }
104*9712c20fSFrederick Mayle }
105*9712c20fSFrederick Mayle
106*9712c20fSFrederick Mayle BPLOG_IF(ERROR, !platform_exploitability) <<
107*9712c20fSFrederick Mayle "No Exploitability module for platform: " <<
108*9712c20fSFrederick Mayle process_state->system_info()->os;
109*9712c20fSFrederick Mayle return platform_exploitability;
110*9712c20fSFrederick Mayle }
111*9712c20fSFrederick Mayle
AddressIsAscii(uint64_t address)112*9712c20fSFrederick Mayle bool Exploitability::AddressIsAscii(uint64_t address) {
113*9712c20fSFrederick Mayle for (int i = 0; i < 8; i++) {
114*9712c20fSFrederick Mayle uint8_t byte = (address >> (8*i)) & 0xff;
115*9712c20fSFrederick Mayle if ((byte >= ' ' && byte <= '~') || byte == 0)
116*9712c20fSFrederick Mayle continue;
117*9712c20fSFrederick Mayle return false;
118*9712c20fSFrederick Mayle }
119*9712c20fSFrederick Mayle return true;
120*9712c20fSFrederick Mayle }
121*9712c20fSFrederick Mayle
122*9712c20fSFrederick Mayle } // namespace google_breakpad
123*9712c20fSFrederick Mayle
124