Research on Automatic Exploitation of House of Spirit Heap Overflow Vulnerability

Minglei Li, Yuliang Lu, Hui Huang, Chao Zhang, Jiazhen Zhao · 2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC) · 2020

Existing vulnerability detection systems cannot effectively detect and utilize house of spirit type heap overflow vulnerabilities. This article summarizes the characteristics of the house of spirit attack, establishes a house of spirit utilization model, and forms a prototype system HCRAX based on this. HCRAX uses stain analysis and symbolic execution technology to monitor the key information of symbolic data that reaches the trigger point of the vulnerability, construct data constraints that trigger the house of spirit vulnerability, and solve the constraint conditions to determine whether it is possible to generate code that automatically exploits the vulnerability. By comparing with CRAX, HCRAX can realize the automatic exploitation of the house of spirit loopholes in some test programs, but none of them can be implemented, which proves the rationality of the model.

Read the paper · More papers on PaperTik