Windows debugging/vulnerability analysis



Hi,

I am looking for some resources on analyzing vulnerabilities in Windows
drivers and/or the kernel. Specifically I am interested in the flaw in
srv.sys as detailed in MS06-035. I'm really looking for details on how
to get useful information out of a debugger at that level, not being a
Windows person myself. Can anyone recommend some reading material?

Thanks,
Tyler



---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: Obsoleteness of X concept
    ... What if we go more further and embed second layer into new kernel ... be exchanged that easily as user mode ... Compare this to the old printer driver model of windows which also had ... kernel mode drivers. ...
    (comp.os.linux.x)
  • Re: Writing/assembling a full operating system
    ... I'm user of Microsoft Windows and a set of different GNU/Linux flavours ... Kernel compilation: compiling a kernel is a target only for trained ... Drivers: GNU/Linux uses drivers as kernel modules, and should be, in ...
    (comp.os.misc)
  • Re: Parallel XGA-2 concept
    ... "Drivers originally written using the Windows NT ... The biggest change is the move of GDI and graphics drivers into the ... into the kernel address space. ...
    (comp.sys.ibm.ps2.hardware)
  • Re: Whats up with the translucent menu?
    ... on Windows is to show Windows users what Mac software is like. ... Developer tools are the real news for Leopard. ... Apple is still supporting 32 bit drivers and software. ... which gives the kernel 4 GB address space like ...
    (comp.sys.mac.advocacy)
  • Re: Large initrd [Was: Re: booting problem (udev related?)]
    ... kernel anyway, or do they get unloaded during boot? ... Perhaps the installer system should ... get prompted for the drivers if Windows doesn't have them. ...
    (Debian-User)