(logo)
(navigation image)
Home Animation & Cartoons | Arts & Music | Computers & Technology | Cultural & Academic Films | Ephemeral Films | Home Movies | Movies | News & Public Affairs | Non-English Videos | Open Source Movies | Prelinger Archives | Spirituality & Religion | Sports Videos | Videogame Videos | Vlogs | Youth Media

Search: Advanced Search

Anonymous User (login or join us)Upload

View movie

[item image]
View thumbnails

Play / Download (help[help])

(125 MB)Ogg Video
(136 MB)512Kb MPEG4
(249 MB)DivX


All Files: HTTP

Resources

Bookmark

ReconRecon 2006 - Alex Ionescu - Subverting Windows 2003 Service Pack 1 Kernel Integrity Protection (2006)

Windows 2003 Service Pack 1 introduces new features into the kernel which protect against previous methods of accessing kernel memory from user mode without the usage of a driver. For example, both the usage of the DevicePhysicalMemory section as well as of the ZwSystemDebugControl APIs has now been completely blocked, meaning that editing kernel memory through physical addresses, installing a callgate or using IDT modifications are not possible methods of violating the ring privilege level.

Unfortunately, it is the authors' belief that many legitimate applications need access to physical memory from user-mode, without the intent of accessing kernel mode memory. Such applications, for example, might need to map the BIOS/Video ROM, or access ACPI tables.

This presentation will detail a method of bypassing one of these new security measures, to give physical access back to user mode applications as well as re-enabling ZwSystemDebugControl, by relying on a previously undiscovered flaw in Windows, accessible only to administrators. A simple solution to this flaw will also be given. As well, this presentation will shed light into the new Win32 APIs exposed in Windows 2003 Service Pack 1 and above, EnumSystemFirmwareTables and GetSystemFirmwareTable, in order to provide hardware manufacturers with a possible way to restore lost functionality of user-mode diagnostic or other programs which accessed device-specific physical memory. Obtaining a SYSTEM primary token, VDM initialization and a new method of transferring from Ring 3 to Ring 0 without the usage of a driver are the main topics which will be discussed.

Bio:
http://www.tinykrnl.org


This movie is part of the collection: Open Source Movies

Producer: Recon
Production Company: Recon Conference
Audio/Visual: sound, color
Keywords: Recon; Reverse Engineering; Conference; Montreal; Security
Contact Information: http://recon.cx


Individual Files

Movie FilesDivXOgg Video512Kb MPEG4
T15-Recon2006-Alex_Ionescu-Subverting_Windows2003SP1_kernel_integrity_protection249 MB125 MB136 MB

Be the first to write a review
Downloaded 361 times
Reviews


Terms of Use (10 Mar 2001)