today-0day
NotionGithubSiteContact
English
English
  • Introduction
    • ๐ŸšฉWindows Driver 0-day Research
    • ๐Ÿซ‚Team. ์šฐ๋ฆฌ ์˜ค๋Š˜๋ถ€ํ„ฐ 0-day
  • backgrounds
    • Windows Driver
    • Related Works
  • Our Approach
    • ๊ฐœ์š”
    • ๐Ÿ‡Init Analyzer
    • ๐Ÿ˜กangr-PT
    • ๐ŸฅŒMS Fuzzer
      • Playmaker mode
      • Qemu-nyx
      • Redqueen
      • Multiple Driver Tracing
      • Call Stack Parser
    • How to Use
  • Appendix
    • References
    • ๐Ÿ“ŽTeam page
    • Achievments
Powered by GitBook
On this page
  1. Our Approach
  2. MS Fuzzer

Multiple Driver Tracing

PreviousRedqueenNextCall Stack Parser

Multiple Driver Tracing

์‹ค์ œ ํ”„๋กœ๊ทธ๋žจ์˜ ๋“œ๋ผ์ด๋ฒ„๋Š” ์—ฌ๋Ÿฌ ๊ฐœ์˜ ๋“œ๋ผ์ด๋ฒ„๋ผ๋ฆฌ ์ƒํ˜ธ ์ž‘์šฉํ•˜๋ฉฐ ๋™์ž‘ํ•ฉ๋‹ˆ๋‹ค.

๋งŒ์•ฝ ๋กœ๋“œ๋˜์ง€ ์•Š์€ ๋“œ๋ผ์ด๋ฒ„์— ์š”์ฒญ์„ ๋ณด๋‚ผ ์‹œ์— ์˜๋ฏธ์—†๋Š” Crash๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

์ด๋ฅผ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด GUI Installer๋ฅผ ํ†ตํ•ด ์‹ค์ œ ํ™˜๊ฒฝ๊ณผ ๋™์ผํ•˜๊ฒŒ ๋งž์ถฐ์ค€ ์ดํ›„ Intel PT Range๋ฅผ ์—ฌ๋Ÿฌ ๋“œ๋ผ์ด๋ฒ„๋กœ ์ ์šฉํ•˜์—ฌ ์‹ค์ œ ๋“œ๋ผ์ด๋ฒ„๋ผ๋ฆฌ์˜ ํ†ต์‹ ๋„ ์ปค๋ฒ„๋ฆฌ์ง€์— ๋ฐ˜์˜ํ•˜์—ฌ ํผ์ง•ํ•˜์˜€์Šต๋‹ˆ๋‹ค.

๐ŸฅŒ