enovella/TEE-reversing

GitHub: enovella/TEE-reversing

一个精选的 TEE 与 ARM TrustZone 逆向工程及安全研究公共资源汇总列表,涵盖多个厂商的实现分析、漏洞利用和模糊测试资料。

Stars: 1033 | Forks: 119

# TEE 基础与概述 - 可信执行环境介绍:ARM 的 TrustZone - https://blog.quarkslab.com/introduction-to-trusted-execution-environment-arms-trustzone.html - TEE 介绍(原题:TEEを中心とするCPUセキュリティ機能の動向 ) - https://seminar-materials.iijlab.net/iijlab-seminar/iijlab-seminar-20181120.pdf - 攻击 ARM 的 TrustZone - https://blog.quarkslab.com/attacking-the-arms-trustzone.html - ARM TrustZone 安全白皮书 - http://infocenter.arm.com/help/topic/com.arm.doc.prd29-genc-009492c/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf - ARM TrustZone 网站 - https://developer.arm.com/ip-products/security-ip/trustzone - TrustZone 解析:架构特性与用例 - http://sefcom.asu.edu/publications/trustzone-explained-cic2016.pdf - 移动设备上的可信执行 - https://netsec.ethz.ch/publications/papers/paper-hyperphone-TRUST-2012.pdf - 揭秘 ARM TrustZone:全面综述 - https://www.researchgate.net/profile/Nuno_Santos9/publication/330696364_Demystifying_Arm_TrustZone_A_Comprehensive_Survey/links/5c6ff1a792851c6950379cdd/Demystifying-Arm-TrustZone-A-Comprehensive-Survey.pdf - 理解可信执行环境与 Arm TrustZone(作者:Azeria) - https://azeria-labs.com/trusted-execution-environments-tee-and-trustzone/ - SoK:理解 TrustZone 辅助的 TEE 系统中普遍存在的安全漏洞 - https://www.cs.purdue.edu/homes/pfonseca/papers/sp2020-tees.pdf - 移动安全的启程(作者:Jonathan Levin) - https://papers.put.as/papers/ios/2016/TrustZone.pdf - ARM 向 TrustZone 的演进(作者:Jonathan Levin) - http://technologeeks.com/files/TZ.pdf # TEE 漏洞利用/安全分析 ## HiSilicon/Huawei (TrustedCore) - Android 上的 TrustZone 漏洞利用 (BH-US 2015) 作者:Di Shen(@returnsme) - https://www.blackhat.com/docs/us-15/materials/us-15-Shen-Attacking-Your-Trusted-Core-Exploiting-Trustzone-On-Android-wp.pdf - EL3 之旅:获取 Android 手机的最高权限 (Infiltrate19) - https://speakerdeck.com/hhj4ck/el3-tour-get-the-ultimate-privilege-of-android-phone - 论文:[infiltrate.pdf](https://github.com/enovella/TEE-reversing/blob/master/Papers/infiltrate.pdf) - 视频:https://vimeo.com/335948808 - Nailgun:打破 ARM 设备中的权限隔离(仅限 PoC #2) - https://github.com/ningzhenyu/nailgun - Nick Stephens:有人如何用鼻子解锁你的手机。(展示了 NWd <> SWd 通信及漏洞利用的宏观图景)GeekPwn 2016 - https://fr.slideshare.net/GeekPwnKeen/nick-stephenshow-does-someone-unlock-your-phone-with-nose ## Qualcomm (QSEE) - 对信任 TrustZone 的思考 (2014) - https://www.blackhat.com/docs/us-14/materials/us-14-Rosenberg-Reflections-on-Trusting-TrustZone.pdf - 在任何上下文中获取 TrustZone 内核的任意代码执行权限 (28/03/2015) - http://bits-please.blogspot.com/2015/03/getting-arbitrary-code-execution-in.html - 探索 Qualcomm 的 TrustZone 实现 (04/08/2015) - http://bits-please.blogspot.com/2015/08/exploring-qualcomms-trustzone.html - 针对 MSM8974 的完整 TrustZone 漏洞利用 (10/08/2015) - http://bits-please.blogspot.com/2015/08/full-trustzone-exploit-for-msm8974.html - TrustZone 内核提权 (CVE-2016-2431) - http://bits-please.blogspot.com/2016/06/trustzone-kernel-privilege-escalation.html - 世界大战 - 从 QSEE 劫持 Linux 内核 - http://bits-please.blogspot.com/2016/05/war-of-worlds-hijacking-linux-kernel.html - QSEE 提权漏洞与利用 (CVE-2015-6639) - http://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html - 探索 Qualcomm 的安全执行环境 (26/04/2016) - http://bits-please.blogspot.com/2016/04/exploring-qualcomms-secure-execution.html - 从零权限提权至 Android mediaserver (CVE-2014-7920 + CVE-2014-7921) - http://bits-please.blogspot.com/2016/01/android-privilege-escalation-to.html - 信任危机:利用 TrustZone TEE (24 July 2017) - https://googleprojectzero.blogspot.com/2017/07/trust-issues-exploiting-trustzone-tees.html - 破坏法则。审查 Qualcomm ARM64 TZ 与 Android 上基于硬件的安全启动 (4-9.x) - https://github.com/bkerler/slides_and_papers/blob/master/QualcommCrypto.pdf - 技术报告:从 Qualcomm 硬件支持的 Keystore 中提取私钥 CVE-2018-11976 (NCC) - https://www.nccgroup.trust/us/our-research/private-key-extraction-qualcomm-keystore/ - Qualcomm TrustZone 整数符号 bug (12/2014) - https://fredericb.info/2014/12/qpsiir-80-qualcomm-trustzone-integer.html - Qualcomm TrustZone 应用模糊测试之路 (RECON Montreal 2019) - https://cfp.recon.cx/media/tz_apps_fuzz.pdf - 针对 TrustZone 的降级攻击 - http://ww2.cs.fsu.edu/~ychen/paper/downgradeTZ.pdf ### Motorola (Qualcomm SoC) - 解锁 Motorola Bootloader (10/02/2016) - http://bits-please.blogspot.com/2016/02/unlocking-motorola-bootloader.html ### HTC (Qualcomm SoC) - 危险地带:TrustZone 中的漏洞 (14/08/2014) - https://atredispartners.blogspot.com/2014/08/here-be-dragons-vulnerabilities-in.html ## Trustonic (Kinibi & MobiCore) - 拆解你的手机:第一、二、三部分 - https://medium.com/taszksec/unbox-your-phone-part-i-331bbf44c30c - https://medium.com/taszksec/unbox-your-phone-part-ii-ae66e779b1d6 - https://medium.com/taszksec/unbox-your-phone-part-iii-7436ffaff7c7 - https://github.com/puppykitten/tbase - https://github.com/puppykitten/tbase/blob/master/unboxyourphone_ekoparty.pdf - KINIBI TEE:可信应用漏洞利用 (2018-12-10) - https://www.synacktiv.com/posts/exploit/kinibi-tee-trusted-application-exploitation.html - Eloi Sanfelix 的三星 Exynos 设备 TEE 漏洞利用:第一、二、三、四部分 - https://labs.bluefrostsecurity.de/blog/2019/05/27/tee-exploitation-on-samsung-exynos-devices-introduction/ - https://labs.bluefrostsecurity.de/files/TEE.pdf - 视频:(Infiltrate 2019) https://vimeo.com/335947683 - 破解三星的 ARM TrustZone (BlackHat USA 2019) - 演示文稿:https://i.blackhat.com/USA-19/Thursday/us-19-Peterlin-Breaking-Samsungs-ARM-TrustZone.pdf - 视频:https://www.youtube.com/watch?v=uXH5LJGRwXI&list=PLH15HpR5qRsWrfkjwFSI256x1u2Zy49VI&index=30 - 在 TrustZone TEE 上启动反馈驱动的模糊测试 (HITBGSEC2019) - https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf - 深入了解三星的 Trustzone - (第一部分 - 介绍) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-1.html - (第二部分 - 模糊测试 TAs) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.html - (第三部分 - 利用 EL3) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-3.html ## Samsung (TEEGRIS) - 破坏 TEE 安全: - (第一部分 - 介绍) https://www.riscure.com/blog/tee-security-samsung-teegris-part-1 - (第二部分 - 利用 TAs) https://www.riscure.com/blog/tee-security-samsung-teegris-part-2 - (第三部分 - TAs > TOS 提权) https://www.riscure.com/blog/tee-security-samsung-teegris-part-3 - 由 @astarasikov 逆向工程三星 Exynos 9820 bootloader 和 TZ - http://allsoftwaresucks.blogspot.com/2019/05/reverse-engineering-samsung-exynos-9820.html - 挖掘 S21 的 10ADAB1E 固件漏洞 (OffensiveCon 2022) - https://www.dropbox.com/s/2f14ga52jguu5cy/OffensiveCon%202022%20-%20Bug%20Hunting%20S21s%2010ADAB1E%20FW.pdf?dl=0 - 由 @TwizzyIndy 带来的从旧版三星 Exynos Trustlet 漏洞中学习 - https://twizzyindy.github.io/android/exynos/2026/01/06/learning-exynos-trustlet-en.html ## Apple (Secure Enclave) - 揭秘 Secure Enclave Processor,作者:Tarjei Mandt, Mathew Solnik 和 David Wang - http://mista.nu/research/sep-paper.pdf - *演示文稿* https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf ## Intel (Intel SGX) - Intel SGX 解析,作者:Victor Costan 和 Srinivas Devadas - https://css.csail.mit.edu/6.858/2017/readings/costan-sgx.pdf # TEE 模糊测试 - PARTEMU:使用模拟技术实现对真实世界 TrustZone 软件的动态分析 - https://people.eecs.berkeley.edu/~rohanpadhye/files/partemu-usenixsec20.pdf - Qualcomm TrustZone 应用模糊测试之路 - https://research.checkpoint.com/the-road-to-qualcomm-trustzone-apps-fuzzing/ - https://cfp.recon.cx/media/tz_apps_fuzz.pdf - 在 TrustZone TEE 上启动反馈驱动的模糊测试 (HITB GSEC 2019 新加坡) - 演示文稿:https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf - 视频:https://www.youtube.com/watch?v=yb7KGznzczs - 使用 AFL 模糊测试嵌入式(可信)操作系统 (Martijn Bogaard | nullcon Goa 2019) OP-TEE - 演示文稿:https://nullcon.net/website/archives/pdf/bangalore-2019/fuzzing-embedded-(trusted)-operating-systems%20using-AFL.pdf - 视频:https://www.youtube.com/watch?v=AZhxZlwZ160 - 网络研讨会:https://www.youtube.com/watch?time_continue=12&v=ROyD9RTMePA - SAN19-225 使用 AFL 模糊测试嵌入式(可信)操作系统 (Martijn Bogaard) OP-TEE - 视频:https://www.youtube.com/watch?v=7bYAwaJ7WZw # TEE 安全启动 - 逆向工程三星6 SBOOT - 第一与第二部分 - https://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-i.html - https://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-ii.html - TEE 的安全初始化:当安全启动失效时 (EuskalHack 2017) - https://www.riscure.com/uploads/2017/08/euskalhack_2017_-_secure_initialization_of_tees_when_secure_boot_falls_short.pdf - Amlogic S905 SoC:绕过(并不那么安全的)安全启动以转储 BootROM - https://fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html#amlogic-s905-soc-bypassing-not-so - Qualcomm 安全启动与镜像认证技术概述 - https://www.qualcomm.com/documents/secure-boot-and-image-authentication-technical-overview-v20 - 破坏三星的信任根 - 利用三星安全启动 (BlackHat 2020) - https://teamt5.org/en/posts/blackhat-s-talk-breaking-samsung-s-root-of-trust-exploiting-samsung-secure-boot/ - 基于 ARM 的 SoC 中安全启动状态概述(硬件辅助可信计算分会场 - Maciej Pijanowski- FOSDEM 2021) - https://archive.fosdem.org/2021/schedule/event/tee_arm_secboot/attachments/paper/4635/export/events/attachments/tee_arm_secboot/paper/4635/Overview_of_Secure_Boot_in_Arm_based_SoCs.pdf - 深入Android可信应用漏洞挖掘与模糊测试 (Kanxue SDC 2023) - https://github.com/guluisacat/MySlides/blob/main/KanxueSDC2023/%E3%80%90%E8%AE%AE%E9%A2%98%E3%80%91%E6%B7%B1%E5%85%A5Android%E5%8F%AF%E4%BF%A1%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E%E6%8C%96%E6%8E%98.pdf # TEE 视频 - Ekoparty-13 (2017) Daniel Komaromy - 拆解你的手机 - 探索并破坏三星的 TrustZone 沙箱 - 视频:https://www.youtube.com/watch?v=L2Mo8WcmmZo - 演示文稿:https://github.com/puppykitten/tbase/blob/master/unboxyourphone_ekoparty.pdf - Daniel Komaromy - 进入 Snapdragon (2014-10-11) - https://www.youtube.com/watch?v=2wJRnewVE-g - BSides DC 2018 & DerbiCon VIII - 鼻息之间:利用 TrustZone 漏洞绕过华为指纹认证,作者 Nick Stephens - https://www.youtube.com/watch?v=QFFhdqP7Dxg - https://www.youtube.com/watch?v=MdoGCXGHGnY - 虫灾降临:探索 ARM TrustZone 架构中的漏洞,作者 Josh Thomas 和 Charles Holmes,2015年9月9-11日奥地利维也纳 Android 安全研讨会 - https://www.youtube.com/watch?v=vxNGgOR-iVM - Android 与可信执行环境,作者 Jan-Erik Ekberg (Trustonic),2015年9月9-11日奥地利维也纳 Android 安全研讨会 - https://www.youtube.com/watch?v=5542lEk3OAM - 34C3 2017 - 主机安全 - Switch 作者:Plutoo, Derrek 和 Naehrwert - https://media.ccc.de/v/34c3-8941-console_security_-_switch - 34C3 2017 - 仅有 TrustZone 是不够的,作者 Pascal Cotret - https://media.ccc.de/v/34c3-8831-trustzone_is_not_enough - RootedCON 2017 - 你母亲从未告诉过你的关于可信执行环境的真相... 作者:José A. Rivas - *西班牙语原声音频* https://www.youtube.com/watch?v=lzrIzS84mdk - *英语翻译* https://www.youtube.com/watch?v=Lzb5OfE1M7s - BH US 2015 - 移动设备上的指纹:滥用与泄露 - https://www.youtube.com/watch?v=7NkojB9gLXM - No ConName 2015 - (不可)信的执行环境,作者 Pau Oliva - 视频:*仅限西班牙语音频* https://vimeo.com/150787883 - 演示文稿:https://t.co/vFATxEa7sy - BH US 2014 - 对信任 TrustZone 的思考,作者 Dan Rosenberg - https://www.youtube.com/watch?v=7w40mS5yLjc - 给傻瓜准备的 ARM TrustZone,作者 Tim Hummels - https://www.youtube.com/watch?v=ecBByjwny3s # 应用于 TEE 的微架构攻击 - ARMageddon:针对移动设备的 Cache 攻击 - [论文] https://www.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_lipp.pdf - [相关工具] https://github.com/IAIK/armageddon - Cache 存储信道:由别名驱动的攻击与经过验证的对策。 - https://www.kth.se/polopoly_fs/1.641701.1550155969!/R.Guanciale.pdf - 34C3 - 针对可信执行环境的微架构攻击 - https://media.ccc.de/v/34c3-8950-microarchitectural_attacks_on_trusted_execution_environments - TruSpy:ARM 设备上来自安全世界的 Cache 侧信道信息泄露 - https://eprint.iacr.org/2016/980.pdf # 工具 ## 模拟 - 针对 Exynos9820 S-Boot 的 QEMU 支持 - https://github.com/astarasikov/qemu - 在 QEMU 中模拟 Exynos 4210 BootROM - https://fredericb.info/2018/03/emulating-exynos-4210-bootrom-in-qemu.html#emulating-exynos-4210-bootrom-in-qemu ## 逆向 - TZAR 解包器 - https://gist.github.com/astarasikov/f47cb7f46b5193872f376fa0ea842e4b#file-unpack_startup_tzar-py - IDA MCLF 加载器 - https://github.com/ghassani/mclf-ida-loader - Ghidra MCLF 加载器 - https://github.com/NeatMonster/mclf-ghidra-loader # 其他有用资源 - ARM Trusted Firmware:针对 Cortex A 和 Cortex M 的安全世界参考实现 - https://www.trustedfirmware.org/ - OP-TEE:基于开源 ARM TrusZone 的 TEE - https://www.op-tee.org/ - 信任危机:利用 TrustZone TEE,Project Zero 团队出品 - https://googleprojectzero.blogspot.com/2017/07/trust-issues-exploiting-trustzone-tees.html - 回旋镖:利用可信执行环境中的语义鸿沟 (A.Machiry) 2017 - https://pdfs.semanticscholar.org/f62b/db9f1950329f59dc467238737d2de1a1bac4.pdf (演示文稿) - http://sites.cs.ucsb.edu/~cspensky/pdfs/ndss17-final227.pdf (论文) - https://github.com/ucsb-seclab/boomerang (工具) - TEE 研究(一些用于 TEE 研究的实用 IDA 和 Ghidra 插件) - https://github.com/bkerler/tee_research
标签:云资产清单, 可信执行环境, 学习资源, 目录枚举, 移动安全, 逆向工程