BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Advanced ROP Framework: Pushing ROP to Its Limits\n 
   When: Sunday\, Aug 13\, 11:00 - 11:45 PDT\n   Where: Caesars Forum - For
 um - 105\,135\,136 - Track 1 - [1]Map\n   Speakers:Bramwell Brizendine\,Sh
 iva Shashank Kusuma\n\n   SpeakerBio:Bramwell Brizendine \, Assistant Prof
 essor at University of\n   Alabama in HuntsvilleDr.\n   Dr. Bramwell Brize
 ndine completed his Ph.D. in Cyber Operations\, for\n   which he did his d
 issertation on Jump-Oriented Programming\, a hitherto\n   seldom-studied a
 nd poorly understood subset of code-reuse attacks.\n\n   Bramwell is now a
 n Assistant Professor of Computer Science at the\n   University of Alabama
  in Huntsville\; he previously was an Assistant\n   Professor and the Dire
 ctor of the Vulnerability and Exploitation\n   Research for Offensive and 
 Novel Attacks (VERONA Lab) at Dakota State\n   University\, specializing i
 n vulnerability research\, software\n   exploitation\, and the development
  of new\, cutting-edge tools and\n   techniques with respect to software e
 xploitation and malware analysis.\n   Bramwell has taught numerous undergr
 aduate\, graduate and doctoral\n   level courses in software exploitation\
 , reverse engineering\, malware\n   analysis and offensive security. Bramw
 ell was a PI on a $300\,000\n   NSA/NCAE research grant\, which culminated
  in the release of a\n   shellcode emulator\, SHAREM\, in September 2022. 
 Bramwell has been a\n   speaker at many top security conferences\, includi
 ng DEF CON\, Hack in\n   the Box Amsterdam\, @Hack\, Black Hat Middle East
 \, Black Hat Asia\, Black\n   Hat Europe\, Wild West Hackin’ Fest\, and 
 more.\n\n\n   SpeakerBio:Shiva Shashank Kusuma \, Master's Student at Univ
 ersity of\n   Alabama in Huntsville\n   Shiva Shashank Kusuma\, a Computer
  Science Master's student at the\n   University of Alabama in Huntsville\,
  has a deep interest in software\n   engineering and cybersecurity. When n
 ot at work\, Shiva enjoys reading\n   about Blockchain\, Web3\, and AI.\n\
 n   Description:\n   This research provides innovative contributions to re
 turn-oriented\n   programming (ROP)\, not seen before. We introduce ROP RO
 CKET\, a\n   cutting-edge ROP framework\, to be released at DEF CON. With 
 ROCKET\,\n   when attacking 32-bit applications\, we can switch between x8
 6 and x64\n   at will\, by invoking a special ROP Heaven's Gate technique\
 , thereby\n   expanding the attack surface. We will discuss the ramificati
 ons of\n   this novel approach.\n\n   Bypassing DEP via ROP is typically s
 traightforward\, using WinAPIs such\n   as VirualProtect and VirtualAlloc.
  We demonstrate an alternative:\n   using Windows syscalls. In fact\, ROCK
 ET provides automatic ROP chain\n   construction to bypass ROP using Windo
 ws syscalls. While extremely\n   trendy\, Windows syscalls are only very r
 arely used in ROP.\n\n   One problem with automatic chain construction is 
 bad chars or bad\n   bytes. We demonstrate how ROCKET allows us to use vir
 tulally any\n   gadget whose address contains bad bytes. With this approac
 h\, automatic\n   ROP chain construction is far less likely to fail. Thus\
 , we overcome\n   one of the major obstacles when creating a ROP chain: ba
 d bytes\, which\n   reduces the attack surface needlessly. In fact\, if on
 e wanted\, they\n   could use ROCKET to "obfuscate" any gadget\, obscuring
  what is being\n   done.\n\n   This presentation will do the seemingly imp
 ossible - and surprise even\n   veteran users of ROP.\n\n   REFERENCES:\n\
 n     1. Brizendine\, B.\, Babcock\, A.: A Novel Method for the Automatic\
 n       Generation of JOP Chain Exploits. In: National Cyber Summit. pp.\n
        77–92 (2021)\n\n     2. Min\, J.W.\, Jung\, S.M.\, Lee\, D.Y.\, C
 hung\, T.M.: Jump oriented\n       programming on windows platform (on the
  x86). Lect. Notes Comput.\n       Sci. (including Subser. Lect. Notes Art
 if. Intell. Lect. Notes\n       Bioinformatics). 7335 LNCS\, 376–390 (20
 12). [2]https://doi.org/10.1007/978-3-642-31137-6_29\n\n     3. Erdodi\, L
 .: Attacking x86 windows binaries by jump oriented\n       programming. IN
 ES 2013 - IEEE 17th Int. Conf. Intell. Eng. Syst.\n       Proc. 333–338 
 (2013). [3]https://doi.org/10.1109/INES.2013.6632837\n\n     4. Brizendine
 \, B.\, Babcock\, A.: Pre-built JOP Chains with the JOP\n       ROCKET: By
 passing DEP without ROP. Black Hat Asia. (2021)\n\n     5. One\, A.: Smash
 ing the stack for fun and profit. Phrack Mag. 7\,\n       14–16 (1996)\n
 \n     6. Designer\, S.: “Return-to-libc” attack.\, [4]https://seclist
 s.org/bugtraq/1997/Aug/63\n\n     7. Shacham\, H.: The geometry of innocen
 t flesh on the bone:\n       Return-into-libc without function calls (on t
 he x86). Proc. ACM\n       Conf. Comput. Commun. Secur. 552–561 (2007). 
 [5]https://doi.org/10.1145/1315245.1315313\n\n     8. Roemer\, R.\, Buchan
 an\, E.\, Shacham\, H.\, Savage\, S.:\n       Return-Oriented Programming 
 : Systems \, Languages \, and\n       Applications. ACM Trans. Inf. Syst. 
 Secur. 15\, 1–36 (2012)\n\n     9. Buchanan\, E.\, Roemer\, R.\, Savage\
 , S.\, Shacham\, H.:\n       Return-oriented programming: Exploitation wit
 hout code injection.\n       Black Hat. 8\, (2008)\n\n     10. PaX\, T.: P
 aX address space layout randomization (ASLR).\n       http//pax. grsecurit
 y. net/docs/aslr. txt. (2003)\n\n     11. Mark E\, R.\, Alex\, I.\, others
 : Windows Internals\, Part 2\, (2012)\n\n     12. Shacham\, H.\, Page\, M.
 \, Pfaff\, B.\, Goh\, E.-J.\, Modadugu\, N.\,\n       Boneh\, D.: On the e
 ffectiveness of address-space randomization.\n       In: Proceedings of th
 e 11th ACM conference on Computer and\n       communications security. pp.
  298–307 (2004)\n\n     13. Vreugdenhil\, P.: Pwn2Own 2010 Windows 7 Int
 ernet Explorer 8\n       exploit.\n\n     14. Gawlik\, R.\, Holz\, T.: ${$
 SoK$}$: Make ${$JIT-Spray$}$ Great\n       Again. In: 12th USENIX Workshop
  on Offensive Technologies (WOOT\n       18) (2018)\n\n     15. Gktas\, E
 .\, Kollenda\, B.\, Koppe\, P.\, Bosman\, E.\, Portokalidis\,\n       G.\,
  Holz\, T.\, Bos\, H.\, Giuffrida\, C.: Position-independent code\n       
 reuse: On the effectiveness of aslr in the absence of information\n       
 disclosure. In: 2018 IEEE European Symposium on Security and\n       Priva
 cy (EuroS&P). pp. 227–242 (2018)\n\n     16. Checkoway\, S.\, Davi\, L.\
 , Dmitrienko\, A.\, Sadeghi\, A.R.\, Shacham\,\n       H.\, Winandy\, M.: 
 Return-oriented programming without returns.\n       Proc. ACM Conf. Compu
 t. Commun. Secur. 559–572 (2010). [6]https://doi.org/10.1145/1866307.186
 6370\n\n     17. Bletsch\, T.\, Jiang\, X.\, Freeh\, V.W.: Jump-oriented p
 rogramming:\n       a new class of code-reuse attack. Proc. 6th Int. Symp.
 \n       Information\, Comput. Commun. Secur. ASIACCS 2011. (2011)\n\n    
  18. Brizendine\, B.: JOP ROCKET repository\, [7]https://github.com/Bw3ll/
 JOP_ROCKET/\n\n     19. Babcock\, A.: IcoFX 2.6 - “.ico” Buffer Overfl
 ow SEH + DEP\n       Bypass using JOP\, [8]https://www.exploit-db.com/expl
 oits/49959\n\n     20. Specter: Sony Playstation 4 (PS4) 5.05 - BPF Double
  Free Kernel\n       Exploit Writeup\, [9]https://www.exploit-db.com/explo
 its/45045\n\n     21. Brizendine\, B.\, Babcock\, A.\, Kramer\, A.: Move O
 ver\, ROP: Towards\n       a Practical Approach to Jump-Oriented Programmi
 ng. HITBMag.\n       121–152 (2021)\n\n     22. Intel Corporation: Contr
 ol-flow Enforcement Technology Preview\,\n       [10]https://software.inte
 l.com/sites/default/files/managed/4d/2a/control-flow-enforcement-technolog
 y-preview.pdf\n\n     23. Schuster\, F.\, Tendyck\, T.\, Liebchen\, C.\, D
 avi\, L.\, Sadeghi\,\n       A.-R.\, Holz\, T.: Counterfeit object-oriente
 d programming: On the\n       difficulty of preventing code reuse attacks 
 in C++ applications.\n       In: 2015 IEEE Symposium on Security and Priva
 cy. pp. 745–762\n       (2015)\n\n     24. Brizendine\, B. Windows Sysca
 lls in Shellcode: Advanced\n       Techniques for Malicious Functionality.
  Hack in the Box Amsterdam\n       (2023).\n\n   '\n\n   1. #CaesarsForumB
 R\n   2. https://doi.org/10.1007/978-3-642-31137-6_29\n   3. https://doi.o
 rg/10.1109/INES.2013.6632837\n   4. https://seclists.org/bugtraq/1997/Aug/
 63\n   5. https://doi.org/10.1145/1315245.1315313\n   6. https://doi.org/1
 0.1145/1866307.1866370\n   7. https://github.com/Bw3ll/JOP_ROCKET/\n   8. 
 https://www.exploit-db.com/exploits/49959\n   9. https://www.exploit-db.co
 m/exploits/45045\n   10. https://software.intel.com/sites/default/files/ma
 naged/4d/2a/control-flow-enforcement-technology-preview.pdf\n\n\n
DTEND:20230813T184500Z
DTSTART:20230813T180000Z
LOCATION:DC - Caesars Forum - Forum - 105\,135\,136 - Track 1
SUMMARY:Advanced ROP Framework: Pushing ROP to Its Limits
END:VEVENT
END:VCALENDAR
