12.07.2015 Views

Bug Hunter Diary

Bug Hunter Diary

Bug Hunter Diary

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Notes1. See SANS Top 20 Internet Security Problems, Threats and Risks (2007Annual Update), http://www.sans.org/top20/2007/.2. See http://www.virustotal.com/.3. See http://www.avast.com/.4. See http://www.vmware.com/.5. WinDbg, the “official” Windows Debugger from Microsoft, is distributed aspart of the free “Debugging Tools for Windows” suite available at http://www.microsoft.com/whdc/DevTools/Debugging/default.mspx.6. You can find a download link for a vulnerable trial version of avast! Professional4.7 at http://www.trapkit.de/books/bhd/.7. See http://www.nirsoft.net/utils/driverview.html.8. See http://www.hex-rays.com/idapro/.9. See Mark E. Russinovich and David A. Solomon, Microsoft Windows Internals:Microsoft Windows Server 2003, Windows XP, and Windows 2000, 4th ed. (Redmond,WA: Microsoft Press, 2005).10. See MSDN Library: Windows Development: Windows Driver Kit: Kernel-Mode Driver Architecture: Reference: Standard Driver Routines: DriverEntryat http://msdn.microsoft.com/en-us/library/ff544113.aspx.11. WinObj is available at http://technet.microsoft.com/en-us/sysinternals/bb896657.aspx.12. The Windows Driver Kit can be downloaded at http://www.microsoft.com/whdc/devtools/WDK/default.mspx.13. See MSDN Library: Windows Development: Windows Driver Kit:Kernel-Mode Driver Architecture: Reference: Standard Driver Routines:Dispatch DeviceControl available at http://msdn.microsoft.com/en-us/library/ff543287.aspx.14. See MSDN Library: Windows Development: Windows Driver Kit: Kernel-Mode Driver Architecture: Reference: Kernel Data Types: System-Defined DataStructures: IRP available at http://msdn.microsoft.com/en-us/library/ff550694.aspx.15. See MSDN Library: Windows Development: Windows Driver Kit: Kernel-Mode Driver Architecture: Design Guide: Writing WDM Drivers: ManagingInput/Output for Drivers: Handling IRPs: Using I/O Control Codes: BufferDescriptions for I/O Control Codes available at http://msdn.microsoft.com/en‐us/library/ff540663.aspx.16. See Jamie Butler, DKOM (Direct Kernel Object Manipulation) (presentation,Black Hat Europe, Amsterdam, May 2004), at http://www.blackhat.com/presentations/win-usa-04/bh-win-04-butler.pdf.17. See http://www.trapkit.de/books/bhd/.18. My security advisory that describes the details of the avast! vulnerabilitycan be found at http://www.trapkit.de/advisories/TKADV2008-002.txt.One Kernel to Rule Them All 111

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!