Return-Oriented Programming
Also known as:ROP
Return-Oriented Programming: Exploit technique that chains existing code fragments instead of injecting new code. ROP is the standard answer to non-executable memory and therefore a core building block of modern binary exploitationBinary ExploitationExploitation of memory or logic errors in compiled applications..
How it works and where it fits
When the stack is no longer executable, no shellcodeShellcodeCompact machine code executed directly by the target process after successful exploitation. can be injected. ROP inverts the problem: instead of supplying new code, existing code is reassembled. The attacker searches the program and its libraries for short instruction sequences ending in a ret — so-called gadgets — and places a chain of gadget addresses onto the overwritten stack. Each ret jumps to the next link, effectively turning the stack into the program. Typical gadgets load registers (pop rdi ; ret), fix stack alignment, or call library functions.
Practical security relevance
ROP requires knowledge of load addresses and is therefore tightly coupled to ASLRAddress Space Layout RandomizationProtection mechanism that randomly arranges memory addresses, thereby making exploits more difficult.: without an address leak there is no basis for the chain. Defensively, control-flow integrity schemes, shadow stacks, and hardware mechanisms such as Intel CET or ARM pointer authentication detect unexpected return targets. When assessing a finding, the decisive question is whether the target binary ships usable gadgets and functions itself — statically linked programs are particularly rich here.
Related concepts
- Binary ExploitationBinary ExploitationExploitation of memory or logic errors in compiled applications.: Exploitation of memory or logic errors in compiled applications.
- Buffer OverflowBuffer OverflowWriting beyond the bounds of a memory buffer, overwriting adjacent data.: Writing beyond the bounds of a memory buffer, overwriting adjacent data.
- Address Space Layout RandomizationAddress Space Layout RandomizationProtection mechanism that randomly arranges memory addresses, thereby making exploits more difficult.: Protection mechanism that randomly arranges memory addresses, thereby making exploits more difficult.
- ShellcodeShellcodeCompact machine code executed directly by the target process after successful exploitation.: Compact machine code executed directly by the target process after successful exploitation.