
HeapHopper est un cadre de vérification de modèle borné pour les implémentations de Heap.
HeapHopper est un framework de vérification de modèles bornée pour les implémentations de tas (heap).

sudo apt update && sudo apt install build-essential python3-dev virtualenvwrapper
git clone https://github.com/angr/heaphopper.git && cd ./heaphopper
mkvirtualenv -ppython3 heaphopper
pip install -e .
build-essential python3-dev virtualenvwrapper
ana angr cle psutil pyelftools pyyaml
# Générer un zoo de permutations
./heaphopper_client.py gen -c analysis.yaml
# Tracer une instance
make -C tests
./heaphopper_client.py trace -c tests/how2heap_fastbin_dup/analysis.yaml -b tests/how2heap_fastbin_dup/fastbin_dup.bin
# Générer un PoC
./heaphopper_client.py poc -c tests/how2heap_fastbin_dup/analysis.yaml -r tests/how2heap_fastbin_dup/fastbin_dup.bin-result.yaml -d tests/how2heap_fastbin_dup/fastbin_dup.bin-desc.yaml -s tests/how2heap_fastbin_dup/fastbin_dup.c -b tests/how2heap_fastbin_dup/fastbin_dup.bin
# Tests
## Afficher le code source
cat tests/how2heap_fastbin_dup/fastbin_dup.c
## Exécuter les tests
tests/test_heaphopper.py
## Afficher le code source du PoC
cat tests/how2heap_fastbin_dup/pocs/malloc_non_heap/fastbin_dup.bin/poc_0_0.c
## Exécuter le PoC
cd tests
./run_poc.sh tests/how2heap_fastbin_dup/pocs/malloc_non_heap/fastbin_dup.bin/bin/poc_0_0.bin
Ce travail a été publié au 27e Symposium USENIX sur la sécurité.
Vous pouvez lire l'article ici.
Citation :
@inproceedings {heaphopper,
author = {Eckert, Moritz and Bianchi, Antonio and Wang, Ruoyu and Shoshitaishvili, Yan and Kruegel, Christopher and Vigna, Giovanni},
title = {HeapHopper: Bringing Bounded Model Checking to Heap Implementation Security},
booktitle = {27th {USENIX} Security Symposium ({USENIX} Security 18)},
year = {2018},
address = {Baltimore, MD},
url = {https://www.usenix.org/conference/usenixsecurity18/presentation/eckert},
publisher = {{USENIX} Association},
}