An Automatic Exploit Generation Method Based on Symbolic Execution

Hao Fang, Wenbo Fen, Menglin Fu · 2018

Return-to-dl-resolve [3] is a general exploit technology that can break through complex protection mechanisms. However, it's hard to be employed for security researchers must understand the principle of ELF dynamic linking and construct shell-code manually. This paper proposes an automatic method to generate Return-to-dl-resolve exploit based on symbolic execution, which provides a symbolic execution environment for ELF executable files, constrains symbolic program state at crash point and solves the constraints through constraint solver, then implements a system called R2d1AEG to generate Return-to-dl-resolve ShellCode automatically. The experimental results show that R2dlAEG system can generate shell-code more quickly and can break both NX and ASLR.

Read the paper · More papers on PaperTik