Opening book details…
Can I read LeapFrog: The Rowhammer Instruction Skip Attack on EtoBox?
LeapFrog: The Rowhammer Instruction Skip Attack by Adiletta, Andrew; Tol, M. Caner; Derya, Kemal; Sunar, Berk; Islam, Saad is a scholarly article available to read on EtoBox.
What is LeapFrog: The Rowhammer Instruction Skip Attack about?
Since its inception, Rowhammer exploits have rapidly evolved into increasingly sophisticated threats compromising data integrity and the control flow integrity of victim processes. Nevertheless, it remains a challenge for an attacker to identify vulnerable targets (i.e., Rowhammer gadgets), understand the outcome of the attempted fault, and formulate an attack that yields useful results. In this paper, we present a new type of Rowhammer gadget, called a LeapFrog gadget, which, when present in the victim code, allows an adversary to subvert code execution to bypass a critical piece of code (e.g., authentication check logic, encryption rounds, padding in security protocols). The LeapFrog gadget manifests when the victim code stores the Program Counter (PC) value in the user or kernel stack (e.g., a return address during a function call) which, when tampered with, repositions the return address to a location that bypasses a security-critical code pattern. This research also presents a systematic process to identify LeapFrog gadgets. This methodology enables the automated detection of susceptible targets and the determination of optimal attack parameters. We first show the attack on a
- Author
- Adiletta, Andrew; Tol, M. Caner; Derya, Kemal; Sunar, Berk; Islam, Saad
- Published
- 2024
- Language
- EN