📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

Blogs >> jms's Blog

Created: Wednesday, June 11 2008 16:04.30 CDT  
Printer Friendly ...
Windows Kernel Exploitation Papers
Author: jms # Views: 2741

I can't remember where all I posted about this, but Kostya and I published a couple of papers today and you can find them

HERE

June 11, 2008: Exploiting Kernel Pool Overflows (Kostya Kortchinsky)  

June 11, 2008: The I2OMGMT Driver Impersonation Attack (Justin Seitz)

Hope you enjoy!


Blog Comments
dennis Posted: Thursday, June 12 2008 13:56.44 CDT
I've seen them announced on DD yesterday and read that paper of yours - really nice stuff! It reminded me of a very similar bug that I have found while having audited an AV filter driver which suffered from pretty the same bug (except that it allowed writing of arbitrary values to user-supplied addresses instead of calling a user supplied address). It's a bit surprising how lacking (if present at all) the checks on the i/o buffers passed from user-mode are. Let's see how long it takes for developers to take this kind of bug a bit more serious - or do they need to be made aware of it first? ;-)
Going for the paper on pool overflows now...

jms Posted: Thursday, June 12 2008 21:45.25 CDT
Thanks! Yes, definitely read Kostya's paper it's far more badass than mine.



Add New Comment
Comment:









There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit