Tetris: Automatic UAF Exploit Generation by Manipulating Layout based on Reactivated Paths
Bin Zhang, Fenglei Deng · 2022
Automatic exploit generation (AEG) for Use-After-Free (UAF) vulnerabilities is a challenging work. Both complex dependencies between program semantics and unpredictable behaviors of the heap allocator increase the difficulty. Existing AEG solutions for UAF vulnerabilities rely on fuzzer to search exploitable states in the whole program space, which shows low efficiency. In this paper, we proposed Tetris, a system that automatically generates exploits for UAF vulnerabilities in user space. Tetris employs a memory collision strategy to automatically infer target memory layout for exploiting after vulnerability triggers. To construct the target layout, we proposed a conception of Reactivated Path (RAP) to represent program semantics for layout manipulation, and built a novel Fast Layout Exploration technique on top of that. Our method works without any knowledge of heap allocators’ internal mechanism and can be easily deployed to other heap memory corruption vulnerabilities by replacing the target layout inference part. We benchmarked Tetris on a set of 19 CTF (capture the flag) programs. The results show that Tetris can generate exploits for 15 of them, and generate inputs for satisfying layout requirements on 2 of them. The evaluation compared with other state-of-the-art AEG tools show that Tetris can generate UAF exploits more efficient.