<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7781143741844512025</id><updated>2012-01-17T21:47:29.045-08:00</updated><title type='text'>Kernel Wars</title><subtitle type='html'>Kernel Exploitation Demystified</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://kernelwars.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781143741844512025/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://kernelwars.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Kernel wars</name><uri>http://www.blogger.com/profile/03821134621975620339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7781143741844512025.post-3337004732123122943</id><published>2007-07-06T01:46:00.000-07:00</published><updated>2007-07-06T02:44:48.984-07:00</updated><title type='text'>Kernel Wars in Vegas!</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Kernel Wars is back, this time at BlackHat USA and DefCon in Las Vegas. Looking forward to seeing you there!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The GDI bug and the FreeBSD 802.11 vulnerability that was discussed in the original BlackHat Europe presentation in Amsterdam will be included this time too. The NetBSD bug have been replaced with... A new NetBSD 0-day. :&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;We have also brought a new co-speaker this time, Claes Nyberg. Claes is also the developer of our in-house fuzzer Itchy, that our main bug hunter Christer Öberg is constantly discovering new vulnerabilities with. :) Claes will talk about his exploit for the OpenBSD ICMPv6 bug, found by Alfredo Ortega from CORE SDI.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Speaking of which, I've noticed that Alfredo will do an entire BlackHat-talk about his own exploit/payload for the bug in question. Will be interesting to see.. :) Bitsec vs CORE, let the best payload win! ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;For DefCon we have included yet another one of Christer's 0-days, and might throw in another one still. There is almost a whole month until Vegas after all.. ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Best Regards,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Joel Eriksson&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;CTO Bitsec&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7781143741844512025-3337004732123122943?l=kernelwars.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kernelwars.blogspot.com/feeds/3337004732123122943/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7781143741844512025&amp;postID=3337004732123122943' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7781143741844512025/posts/default/3337004732123122943'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781143741844512025/posts/default/3337004732123122943'/><link rel='alternate' type='text/html' href='http://kernelwars.blogspot.com/2007/07/kernel-wars-in-vegas.html' title='Kernel Wars in Vegas!'/><author><name>Kernel wars</name><uri>http://www.blogger.com/profile/03821134621975620339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7781143741844512025.post-6041126353276834133</id><published>2007-01-29T06:59:00.001-08:00</published><updated>2007-07-06T02:14:17.736-07:00</updated><title type='text'>Kernel Wars in Amsterdam!</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;This post is about our talk at BlackHat Europe 2007 in Amsterdam.&lt;br /&gt;&lt;br /&gt;Kernel vulnerabilities are often deemed unexploitable or at least unlikely&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; to be exploited reliably. Although it's true that kernel-mode exploitation&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; often presents some new challenges for exploit developers, it still all boils&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; down to "creative debugging" and knowledge about the target in question.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;During our talk we intend to&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; demystify kernel-mode exploitation by demonstrating the&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; analysis and reliable exploitation of three different kernel vulnerabilities&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; without public exploits. From a defenders point of view this could hopefully&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; serve as an eye-opener, as it demonstrates the ineffectiveness of HIDS, NX,&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; ASLR and other protective measures when the kernel itself is being exploited.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The vulnerabilities that will be discussed are:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;- FreeBSD 802.11 Management Frame Integer Overflow (Patched)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;   Found and exploited by Karl Janmar. &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;a href="http://www.signedness.org/advisories/sps-0x1.txt"&gt;Advisory&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;- NetBSD Local Kernel Heap Overflow (Unpatched, 0-day)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;   Found by Christer Öberg, exploited by Christer and Joel Eriksson.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;- Windows (2000 &amp; XP) Local GDI Memory Overwrite (Unpatched)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;   Found by Cesar Cerrudo, exploited by Joel Eriksson. &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;a href="http://projects.info-pull.com/mokb/MOKB-06-11-2006.html"&gt;Advisory&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Unlike most of the 802.11-related bugs that have been found lately the&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; FreeBSD 802.11 vulnerability did not only affect a particular driver, but&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; the 802.11 subsystem itself. Besides being discovered quite a while before&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; the other WLAN-related bugs (summer 2005) it uses a pretty interesting payload, which&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; injects a pure kernel-mode backdoor that communicates through spoofed&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; management frames. The full exploit will be released after the talk.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The GDI bug for Windows 2000 and XP that results in a local privilege&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; escalation when successfully exploited was found by Cesar Cerrudo from&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; Argeniss and reported to Microsoft as early as 2004-10-22. It was made&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; public during MoKB (Month of Kernel Bugs) on 2006-11-06, more than two&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; years later.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amazingly it has still not been patched, perhaps due to Microsoft not&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; taking the threat seriously until they've seen that it can be exploited&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; reliably in practice. Reliable exploitation for Windows 2000 and XP with&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; any and all servicepacks and patches applied will be demonstrated during&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; the talk.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Since we intend to release the NetBSD bug during the talk we will not&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; disclose any details yet, but.. The particularly interesting thing about&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; this bug is that it has been around for almost two decades. It was present&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; in both OpenBSD and FreeBSD until they got rid of the code in question&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; altogether and it most likely still exists in some of the other commercial&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; Unix-systems derived from BSD.&lt;br /&gt;&lt;br /&gt;( Joel Eriksson | Karl Janmar | Christer Öberg @ Bitsec )&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Picture of the 802.11 exploit GUI:&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_-W-VYQIjao0/Rb-SeNO7fjI/AAAAAAAAAAg/9OdgErTGSy8/s1600-h/bod.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_-W-VYQIjao0/Rb-SeNO7fjI/AAAAAAAAAAg/9OdgErTGSy8/s400/bod.png" alt="" id="BLOGGER_PHOTO_ID_5025896756814773810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Picture of the NetBSD exploit:&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_-W-VYQIjao0/Rb-RutO7fiI/AAAAAAAAAAY/SdJ8mf2T26w/s1600-h/netbsd.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_-W-VYQIjao0/Rb-RutO7fiI/AAAAAAAAAAY/SdJ8mf2T26w/s400/netbsd.png" alt="" id="BLOGGER_PHOTO_ID_5025895940770987554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Picture of the GDI exploit:&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_-W-VYQIjao0/Rb-Ys9O7fkI/AAAAAAAAAAw/mj05UDrB1_o/s1600-h/gdipwnx.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_-W-VYQIjao0/Rb-Ys9O7fkI/AAAAAAAAAAw/mj05UDrB1_o/s400/gdipwnx.png" alt="" id="BLOGGER_PHOTO_ID_5025903607287610946" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7781143741844512025-6041126353276834133?l=kernelwars.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kernelwars.blogspot.com/feeds/6041126353276834133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7781143741844512025&amp;postID=6041126353276834133' title='184 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7781143741844512025/posts/default/6041126353276834133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781143741844512025/posts/default/6041126353276834133'/><link rel='alternate' type='text/html' href='http://kernelwars.blogspot.com/2007/01/alive.html' title='Kernel Wars in Amsterdam!'/><author><name>Kernel wars</name><uri>http://www.blogger.com/profile/03821134621975620339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_-W-VYQIjao0/Rb-SeNO7fjI/AAAAAAAAAAg/9OdgErTGSy8/s72-c/bod.png' height='72' width='72'/><thr:total>184</thr:total></entry></feed>
