20.02.2013 Views

Windows RunTime - Hack In The Box 2012 - QuarksLAB

Windows RunTime - Hack In The Box 2012 - QuarksLAB

Windows RunTime - Hack In The Box 2012 - QuarksLAB

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Windows</strong> 8 WinRT - Applications & Components WinRT - <strong>In</strong>ternals <strong>Windows</strong> Store Sandbox Conclusion<br />

Process isolation<br />

Chrome<br />

Low<strong>Box</strong><br />

. . .<br />

Microsoft modified _TOKEN structure<br />

A new syscall NtCreateLow<strong>Box</strong>Token to make a very limited token<br />

Fills new fields<br />

Sets integrity level to low<br />

Changes access rights to the token to TOKEN ALL ACCESS for<br />

itself and TOKEN QUERY for administrators<br />

SepAccessCheck was slightly modified

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!