20.02.2013 Views

Windows RunTime - Hack In The Box 2012 - QuarksLAB

Windows RunTime - Hack In The Box 2012 - QuarksLAB

Windows RunTime - Hack In The Box 2012 - QuarksLAB

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Windows</strong> 8 WinRT - Applications & Components WinRT - <strong>In</strong>ternals <strong>Windows</strong> Store Sandbox Conclusion<br />

Chrome sandbox - Layout<br />

Sandboxed<br />

process<br />

Call to<br />

NtCreateFile<br />

Retrieve the duplicated handle<br />

Notify the HANDLE<br />

TargetNtCreateFile Broker<br />

Write parameters<br />

NtCreateFile<br />

(original)<br />

Shared HANDLE<br />

Shared<br />

memory<br />

Wake the thread up<br />

Retrieve parameters<br />

Write the duplicated handle<br />

NtDuplicateHandle<br />

Access policy

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!