Gollum: Modular and Greybox Exploit Generation for Heap Overflows in Interpreters
Sean Heelan, Tom Melham, Daniel Kroening
Abstract
We present the first approach to automatic exploit generation for heap overflows in interpreters. It is also the first approach to exploit generation in any class of program that integrates a solution for automatic heap layout manipulation. At the core of the approach is a novel method for discovering exploit primitives-inputs to the target program that result in a sensitive operation, such as a function call or a memory write, utilizing attacker-injected data. To produce an exploit primitive from a heap overflow vulnerability, one has to discover a target data structure to corrupt, ensure an instance of that data structure is adjacent to the source of the overflow on the heap, and ensure that the post-overflow corrupted data is used in a manner desired by the attacker. Our system addresses all three tasks in an automatic, greybox, and modular manner. Our implementation is called Gollum, and we demonstrate its capabilities by producing exploits from 10 unique vulnerabilities in the PHP and Python interpreters, 5 of which do not have existing public exploits. CCS CONCEPTS • Security and privacy → Systems security; Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dbcc95b3-4def-4081-90e9-655c625b2d24Cited by top-tier papers22
- LibAFL: A Framework to Build Modular and Reusable FuzzersAndrea Fioraldi, Dominik Christian Maier, Dongjia Zhang, Davide BalzarottiCCS 2022 · 71 citations
- GREBE: Unveiling Exploitation Potential for Linux Kernel BugsZhenpeng Lin, Yueqi Chen, Yuhang Wu, Dongliang Mu et al.S&P 2022 · 47 citations
- A Systematic Study of Elastic Objects in Kernel ExploitationYueqi Chen, Zhenpeng Lin, Xinyu XingCCS 2020 · 35 citations
- HEAPSTER: Analyzing the Security of Dynamic Allocators for Monolithic Firmware ImagesFabio Gritti, Fabio Pagani, Ilya Grishchenko, Lukas Dresel et al.S&P 2022 · 31 citations
- MAZE: Towards Automated Heap Feng ShuiYan Wang, Chao Zhang, Zixuan Zhao, Bolun Zhang et al.USENIX Security 2021 · 25 citations
Builds on6
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing et al.USENIX Security 2018 · 124 citations
- Revery: From Proof-of-Concept to ExploitableYan Wang, Chao Zhang, Xiaobo Xiang, Zixuan Zhao et al.CCS 2018 · 85 citations
- Automatic Heap Layout Manipulation for ExploitationSean Heelan, Tom Melham, Daniel KroeningUSENIX Security 2018 · 62 citations
Related papers
- Automated Exploitable Heap Layout Generation for Heap Overflows Through Manipulation Distance-Guided FuzzingBin Zhang, Jiongyi Chen, Runhao Li, Chao Feng et al.USENIX Security 2023
- Towards Automatic and Precise Heap Layout Manipulation for General-Purpose ProgramsRunhao Li, Bin Zhang, Jiongyi Chen, Wenfeng Lin et al.NDSS 2023
- Nothing is Unreachable: Automated Synthesis of Robust Code-Reuse Gadget Chains for Arbitrary Exploitation PrimitivesNicolas Bailluet, Emmanuel Fleury, Isabelle Puaut, Erven RohouUSENIX Security 2025
- Saphire: Sandboxing PHP Applications with Tailored System Call AllowlistsAlexander Bulekov, Rasoul Jahanshahi, Manuel EgeleUSENIX Security 2021 · 30 citations
- Melting the Flesh of PHP's Memory HardeningYifan Wu, Xiaochuan Yu, Zhiyun QianUSENIX Security 2026
