today-0day
NotionGithubSiteContact
English
English
  • Introduction
    • 🚩Windows Driver 0-day Research
    • πŸ«‚Team. 우리 μ˜€λŠ˜λΆ€ν„° 0-day
  • backgrounds
    • Windows Driver
    • Related Works
  • Our Approach
    • κ°œμš”
    • πŸ‡Init Analyzer
    • 😑angr-PT
    • πŸ₯ŒMS Fuzzer
      • Playmaker mode
      • Qemu-nyx
      • Redqueen
      • Multiple Driver Tracing
      • Call Stack Parser
    • How to Use
  • Appendix
    • References
    • πŸ“ŽTeam page
    • Achievments
Powered by GitBook
On this page
  1. Our Approach

Init Analyzer

Previousκ°œμš”Nextangr-PT

Windows Kernel Driver 취약점을 μ•…μš©ν•˜κΈ° μœ„ν•΄μ„œλŠ” Medium Integrityμ΄ν•˜ κΆŒν•œμ—μ„œ Driver에 값을 전달할 수 μžˆμ–΄μ•Ό ν•©λ‹ˆλ‹€.

μƒμš© ν”„λ‘œκ·Έλž¨μ—μ„œ μ‚¬μš©λ˜λŠ” λ“œλΌμ΄λ²„ 100개 이상을 뢄석해본 κ²°κ³Ό, High Integrityμ΄μƒμ˜ κΆŒν•œμ—μ„œ λ“œλΌμ΄λ²„μ— μ ‘κ·Όν•  수 μžˆλŠ” 사둀도 μ‘΄μž¬ν–ˆμŠ΅λ‹ˆλ‹€.

μ €ν¬λŠ” μƒμš© ν”„λ‘œκ·Έλž¨μ—μ„œ μ‚¬μš©λ˜λŠ” λ“œλΌμ΄λ²„ 식별과 Attack Surfaceλ‘œμ„œ ν™œμš© κ°€λŠ₯성에 λŒ€ν•œ 평가λ₯Ό μ•„λž˜μ˜ 기쀀을 톡해 μžλ™ν™” ν•˜μ˜€μŠ΅λ‹ˆλ‹€.

  • Medium Integrityμ—μ„œ μ ‘κ·Ό κ°€λŠ₯ν•œκ°€

  • ν”„λ‘œκ·Έλž¨ μ„€μΉ˜ μ‹œ μ–΄λ–€ λ“œλΌμ΄λ²„κ°€ μ„€μΉ˜λ˜λŠ”κ°€

πŸ‡