Web Hack List

Collected research

Counterfeit Object-oriented Programming: On the Difficulty of Preventing Code Reuse Attacks in C++ Applications

Counterfeit object-oriented programming chains a C++ program's own virtual functions, driven through an existing loop over attacker-forged objects, so a code-reuse payload needs no return addresses and no injected gadgets. It bypasses coarse-grained CFI and the C++-aware defences CPS, T-VIP, vfGuard and VTint, shown with working exploits for Internet Explorer 10 and Firefox 36.

Record

Researcher
Felix Schuster, Thomas Tendyck, Christopher Liebchen, Lucas Davi, Ahmad-Reza Sadeghi and Thorsten Holz
Published by
ieee-security.org
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Felix Schuster, Thomas Tendyck, Christopher Liebchen, Lucas Davi, Ahmad-Reza Sadeghi and Thorsten Holz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .