How the ELF Ruined Christmas

نویسندگان

  • Alessandro Di Federico
  • Amat Cama
  • Yan Shoshitaishvili
  • Christopher Krügel
  • Giovanni Vigna
چکیده

Throughout the last few decades, computer software has experienced an arms race between exploitation techniques leveraging memory corruption and detection/protection mechanisms. Effective mitigation techniques, such as Address Space Layout Randomization, have significantly increased the difficulty of successfully exploiting a vulnerability. A modern exploit is often two-stage: a first information disclosure step to identify the memory layout, and a second step with the actual exploit. However, because of the wide range of conditions under which memory corruption occurs, retrieving memory layout information from the program is not always possible. In this paper, we present a technique that uses the dynamic loader’s ability to identify the locations of critical functions directly and call them, without requiring an information leak. We identified several fundamental weak points in the design of ELF standard and dynamic loader implementations that can be exploited to resolve and execute arbitrary library functions. Through these, we are able to bypass specific security mitigation techniques, including partial and full RELRO, which are specifically designed to protect ELF data-structures from being coopted by attackers. We implemented a prototype tool, Leakless, and evaluated it against different dynamic loader implementations, previous attack techniques, and reallife case studies to determine the impact of our findings. Among other implications, Leakless provides attackers with reliable and non-invasive attacks, less likely to trigger intrusion detection systems.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

How the ELF Ruined Christmas

Throughout the last few decades, computer software has experienced an arms race between exploitation techniques leveraging memory corruption and detection/protection mechanisms. Effective mitigation techniques, such as Address Space Layout Randomization, have significantly increased the difficulty of successfully exploiting a vulnerability. A modern exploit is often two-stage: a first informati...

متن کامل

Achieving Multimodal Cohesion during Intercultural Conversations

How do English as a lingua franca (ELF) speakers achieve multimodal cohesion on the basis of their specific interests and cultural backgrounds? From a dialogic and collaborative view of communication, this study focuses on how verbal and nonverbal modes cohere together during intercultural conversations. The data include approximately 160-minute transcribed video recordings of ELF interactions ...

متن کامل

Association of Dowling-Degos disease and multiple seborrheick-eratosis in a “Christmas tree pattern”

  Dowling-Degos disease is a rare sporadic or autosomal dominant pigmentary entity, in which clusters of papules and reticulate macules slowly develop with predominance in flexural regions. This entity is due to mutations in the keratin 5 gene, and is related with other cutaneous disorders. We report the sporadic form of Dowling-Degos disease in an elderly man with multiple seborrheickeratosis ...

متن کامل

Extremely Low-Frequency Magnetic Fields and Redox-Responsive Pathways Linked to Cancer Drug Resistance: Insights from Co-Exposure-Based In Vitro Studies

Electrical devices currently used in clinical practice and common household equipments generate extremely low-frequency magnetic fields (ELF-MF) that were classified by the International Agency for Research on Cancer as "possible carcinogenic." Assuming that ELF-MF plays a role in the carcinogenic process without inducing direct genomic alterations, ELF-MF may be involved in the promotion or pr...

متن کامل

Transcriptional regulation of Elf-1: locus-wide analysis reveals four distinct promoters, a tissue-specific enhancer, control by PU.1 and the importance of Elf-1 downregulation for erythroid maturation

Ets transcription factors play important roles during the development and maintenance of the haematopoietic system. One such factor, Elf-1 (E74-like factor 1) controls the expression of multiple essential haematopoietic regulators including Scl/Tal1, Lmo2 and PU.1. However, to integrate Elf-1 into the wider regulatory hierarchies controlling haematopoietic development and differentiation, regul...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015