arrow
返回

SeBROP: blind ROP attacks without returns

delete2022-01-06
delete6
PRE
AI
T
Tianning Zhang *
M
Miao Cai
D
Diming Zhang
黄
黄浩 (Hao Huang)
DOI:10.1007/s11704-021-0342-8delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Currently, security-critical server programs are well protected by various defense techniques, such as Address Space Layout Randomization(ASLR), eXecute Only Memory(XOM), and Data Execution Prevention(DEP), against modern code-reuse attacks like Return-oriented Programming(ROP) attacks. Moreover, in these victim programs, most syscall instructions lack the following ret instructions, which prevents attacks to stitch multiple system calls to implement advanced behaviors like launching a remote shell. Lacking this kind of gadget greatly constrains the capability of code-reuse attacks. This paper proposes a novel code-reuse attack method called Signal Enhanced Blind Return Oriented Programming (SeBROP) to address these challenges. Our SeBROP can initiate a successful exploit to server-side programs using only a stack overflow vulnerability. By leveraging a side-channel that exists in the victim program, we show how to find a variety of gadgets blindly without any pre-knowledges or reading/disassembling the code segment. Then, we propose a technique that exploits the current vulnerable signal checking mechanism to realize the execution flow control even when ret instructions are absent. Our technique can stitch a number of system calls without returns, which is more superior to conventional ROP attacks. Finally, the SeBROP attack precisely identifies many useful gadgets to constitute a Turing-complete set. SeBROP attack can defeat almost all state-of-the-art defense techniques. The SeBROP attack is compatible with both modern 64-bit and 32-bit systems. To validate its effectiveness, We craft three exploits of the SeBROP attack for three real-world applications, i.e., 32-bit Apache 1.3.49, 32-bit ProFTPD 1.3.0, and 64-bit Nginx 1.4.0. Experimental results demonstrate that the SeBROP attack can successfully spawn a remote shell on Nginx, ProFTPD, and Apache with less than 8500/4300/2100 requests, respectively.
Keyword:
code-reuse attack
ROP
signal

期刊

Frontiers of Computer Science 封面图
Frontiers of Computer Science
IF:
4.6
论文数:
1.6K
被引数:
2.8K

机构

H
Hohai University
学者数:
2.3W
论文数: 1.8W
被引数: 2.1W
N
nanjing university
学者数:
7.8W
论文数: 5.6W
被引数: 87
J
jiangsu university of science & technology
学者数:
9.0K
论文数: 6.9K
被引数: 9
学者 查看更多机构
引用论文

引用论文

Metátese de olefinas aplicada ao fechamento de anéis: uma ferramenta poderosa para a síntese de macrociclos naturais
err2008-01-01
err0
errOAAI
errAnderson Rouge dos Santos; Carlos Roland Kaiser; Jean-Pierre Férézou
err分享
err收藏
Retrieval from memory of dietary information
err2006-02-13
err0
PREAI
errAlbert F. Smith; Jared B. Jobe; David J. Mingay
err分享
err收藏
Systematic analysis of human antibody response to ebolavirus glycoprotein reveals high prevalence of neutralizing public clonotypes
err
IF0
err2022-01-13
err0
errOAAI
errElaine C. Chen; Pavlo Gilchuk; Seth J. Zost; Philipp A. Ilinykh; Elad Binshtein; Kai Huang; Luke Myers; Stefano Bonissone; Samuel Day; Chandrahaas R. Kona; Andrew Trivette; Joseph X. Reidy; Rachel E. Sutton; Christopher Gainza; Summer Monroig; Edgar Davidson; Erica Ollmann Saphire; Benjamin J. Doranz; Natalie Castellana; Alexander Bukreyev; Robert H. Carnahan; James E. Crowe
err分享
err收藏
Mission-Level Study of Integrated Gas Turbine and Environmental Control System Architectures
err2018-01-07
err0
PREAI
errMingxuan Shi; Imon Chakraborty; Yu Cai; Jimmy C. Tai; Dimitri N. Mavris
err分享
err收藏
学者 查看更多内容