SLIDE 1
Attacking the Windows Kernel
Below The Root
Jonathan Lindsay, Reverse Engineer in extremis
Attacking the Windows Kernel Below The Root Jonathan Lindsay, - - PowerPoint PPT Presentation
Attacking the Windows Kernel Below The Root Jonathan Lindsay, Reverse Engineer in extremis Introduction Limited to Windows, and aimed at IA32: Outline of protected mode and the kernel Attack vectors Useful tools Examples
Jonathan Lindsay, Reverse Engineer in extremis
– CPU bugs – Operating system design
– StartService, DeviceIoControl, ExtEscape
– ZwSystemDebugControl, ZwSetSystemInformation
– Viruses – DLL (export driver) injection