Exploiting the hard-working DWARF: trojan and exploit techniques with no native executable code
James Oakley, Sergey Bratus · 2011
The study of vulnerabilities and exploitation is one of finding mechanisms affecting the flow of computation and of finding new means to perform unexpected com-putation. In this paper we show the extent to which ex-ception handling mechanisms as implemented and used by gcc can be used to control program execution. We show that the data structures used to store exception han-dling information on UNIX-like systems actually contain Turing-complete bytecode, which is executed by a vir-tual machine during the course of exception unwinding and handling. We discuss how a malicious attacker could gain control over these structures and how such an at-tacker could utilize them once control has been achieved. 1