PwnShield: An Automated Approach to Detect and Exploit Buffer Overflows and Bypassing Modern Mitigation Techniques
摘要
In the dynamic realm of cybersecurity, the perpetual struggle between security systems and malicious exploits persists. Among these threats, buffer overflow vulnerabilities remain a persistent challenge continually adapting to evade modern mitigation techniques such as NX, RELRO, Stack canaries and PIE. To confront these sophisticated threats, our research introduces PwnShield as an advanced program designed to detect and exploit buffer overflow vulnerabilities effectively and bypass modern mitigation methods. Leveraging the robust capabilities of Python’s Pwntools and r2pipe libraries, PwnShield excels in exploitation by combining fuzzing and static binary analysis compared to existing tools like BofAEG and autoBOF, PwnShield demonstrates superior performance and showcases its ability to handle buffer overflow exploitation and bypass a comprehensive range of modern mitigation techniques. PwnShield represents a significant advancement in cybersecurity in an environment where detecting and exploiting buffer overflows presents formidable challenges. With limited research dedicated to addressing these complexities, we are pushing the boundaries of buffer overflow detection and exploitation automation, heralding a new era of progress in the field.