Re: Windows debugging/vulnerability analysis



On 7/27/06, Krpata, Tyler <tkrpata@xxxxxxx> wrote:
Hi,

I am looking for some resources on analyzing vulnerabilities in Windows
drivers and/or the kernel. Specifically I am interested in the flaw in
srv.sys as detailed in MS06-035. I'm really looking for details on how
to get useful information out of a debugger at that level, not being a
Windows person myself. Can anyone recommend some reading material?

I hope you have experience in userspace vulnerability analysis before
you go into the kernel-based stuff. Do you know about SoftICE? It is a
Windows debugger capabable of debugging kernel-based code. There
should be a lot of information to be found on Google.

Good luck.

--
Regards,
Rob klein Gunnewiek

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: Windbg: Disable user mode debugging
    ... >> This group is not applicable because of the win32 in the title. ... So you don't have 64-bit Windows. ... debugger is an extension to ntoskrnl and maybe the hal too. ... I do know that the kernel does not have ...
    (microsoft.public.win32.programmer.kernel)
  • Re: Random reboots
    ... Disable automatic restart on system failure. ... Microsoft Windows Debugger Version 6.9.0003.113 X86 ... Mini Kernel Dump File: Only registers and stack trace are available ...
    (microsoft.public.windowsxp.help_and_support)
  • EEYE: Windows VDM TIB Local Privilege Escalation
    ... Windows VDM TIB Local Privilege Escalation ... Medium (Local Privilege Escalation to Kernel) ...
    (NT-Bugtraq)
  • [Full-Disclosure] EEYE: Windows VDM TIB Local Privilege Escalation
    ... Windows VDM TIB Local Privilege Escalation ... Medium (Local Privilege Escalation to Kernel) ...
    (Full-Disclosure)
  • unsubscribe
    ... delete your Windows partition TODAY! ... >> If you want to build kernel modules, you need to use the kernel headers ... >> I would like to know if anyone had a chance to installed Debian or other ... > I find the evince with Debian has very poor performance when I open ...
    (Debian-User)