Melting the Flesh of PHP's Memory Hardening
Yifan Wu, Xiaochuan Yu, Zhiyun Qian
摘要
Heap allocators are responsible for efficiently allocating or releasing memory on the heap. In addition, they also commonly implement various mitigation measures to defend against heap-based memory corruption. Recently, the PHP project launched a heap hardening initiative aimed at stopping popular heap exploit techniques or restricting the exploit strategy space. In this paper, we conduct the first security study to understand the impact and effectiveness of these new protective measures. We find that while they are effective at stopping current-generation exploits, they fall short against determined attackers who will adapt. Through our analysis, we not only identify the flaw that allows specific mitigations to be bypassed, but also a new suite of novel exploitation strategies that work for the most common vulnerabilities involving out-of-bounds memory write and use-after-free write primitives. Notably, our strategy is generic across the built-in PHP objects and can still work even with a single-byte out-of-bounds memory write primitive. Finally, we evaluate our exploit strategies against five real vulnerabilities in an environment with all evaluated protections enabled. The results show that although the new protection measures can effectively defend against the exploitation of most vulnerabilities, the attack strategies proposed by this work can still make these vulnerabilities exploitable again. The identified flaw has since been patched after our responsible disclosure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- FreeGuard: A Faster Secure Heap AllocatorSam Silvestro, Hongyu Liu, Corey Crosser, Zhiqiang Lin 等CCS 2017 · 被引用 71 次
- Gollum: Modular and Greybox Exploit Generation for Heap Overflows in InterpretersSean Heelan, Tom Melham, Daniel KroeningCCS 2019 · 被引用 50 次
- Guarder: A Tunable Secure AllocatorSam Silvestro, Hongyu Liu, Tianyi Liu, Zhiqiang Lin 等USENIX Security 2018 · 被引用 39 次
- SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux KernelLukas Maar, Stefan Gast, Martin Unterguggenberger, Mathias Oberhuber 等USENIX Security 2024 · 被引用 16 次
- Top of the Heap: Efficient Memory Error Protection of Safe Heap ObjectsKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等CCS 2024 · 被引用 3 次
相关 Paper
- HeapHopper: Bringing Bounded Model Checking to Heap Implementation SecurityMoritz Eckert, Antonio Bianchi, Ruoyu Wang, Yan Shoshitaishvili 等USENIX Security 2018 · 被引用 62 次
- Automatic Heap Layout Manipulation for ExploitationSean Heelan, Tom Melham, Daniel KroeningUSENIX Security 2018 · 被引用 62 次
- Automatic Techniques to Systematically Discover New Heap Exploitation PrimitivesInsu Yun, Dhaval Kapil, Taesoo KimUSENIX Security 2020
- HEAP LOCALIZATION: Cache Side-Channel Based Linux Kernel Heap Exploit TechniquesYoochan Lee, Sihyun Roh, Hyuk Kwon, Byoungyoung Lee 等S&P 2026
- CAMP: Compiler and Allocator-based Heap Memory ProtectionZhenpeng Lin, Zheng Yu, Ziyi Guo, Simone Campanoni 等USENIX Security 2024 · 被引用 14 次
