today-0day
NotionGithubSiteContact
Korean
Korean
  • Introduction
    • ๐ŸšฉWindows Driver 0-day Research
    • ๐Ÿซ‚Team. ์šฐ๋ฆฌ ์˜ค๋Š˜๋ถ€ํ„ฐ 0-day
  • backgrounds
    • Windows Driver
    • Related Works
  • Our Approach
    • ๊ฐœ์š”
    • ๐Ÿ‡Init Analyzer
    • ๐Ÿ˜กangr-PT
    • ๐ŸฅŒMS Fuzzer
      • Playmaker mode
      • Qemu-nyx
      • Redqueen
      • Multiple Driver Tracing
      • Call Stack Parser
    • How to Use
  • Appendix
    • References
    • Achievments
    • ๐Ÿ”—Team page
    • ๐Ÿ”—CODE BLUE 2024
Powered by GitBook
On this page
  1. Our Approach

Init Analyzer

Previous๊ฐœ์š”Nextangr-PT

Last updated 2 months ago

Windows Kernel Driver ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” Medium Integrity์ดํ•˜ ๊ถŒํ•œ์—์„œ Driver์— ๊ฐ’์„ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ƒ์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๋“œ๋ผ์ด๋ฒ„ 100๊ฐœ ์ด์ƒ์„ ๋ถ„์„ํ•ด๋ณธ ๊ฒฐ๊ณผ, High Integrity์ด์ƒ์˜ ๊ถŒํ•œ์—์„œ ๋“œ๋ผ์ด๋ฒ„์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ๋ก€๋„ ์กด์žฌํ–ˆ์Šต๋‹ˆ๋‹ค.

์ €ํฌ๋Š” ์ƒ์šฉ ํ”„๋กœ๊ทธ๋žจ์„ (1) ์–ด๋–ค Kernel Driver๋ฅผ ์„ค์น˜ํ•˜์—ฌ ์‚ฌ์šฉํ•˜๋Š”์ง€, (2) Attack Surface๋กœ์„œ ํ™œ์šฉ ๊ฐ€๋Šฅ์„ฑ(Medium ๊ถŒํ•œ์—์„œ Handle์ด ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ์ง€)์„ ํ™•์ธํ•˜๋Š” ๊ณผ์ •์„ ์ž๋™ํ™”ํ•˜์—ฌ ๋น ๋ฅธ ์‹œ๊ฐ„ ๋‚ด ํŒŒ์•…ํ•˜๊ณ ์ž ํ•˜์˜€์Šต๋‹ˆ๋‹ค.

๊ตฌ์ฒด์ ์ธ ๊ณผ์ •์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  1. Installation์„ ์ˆ˜์ง‘

  2. ์„ค์น˜ ์ „๊ณผ ํ›„ VM์˜ Filesystem๊ณผ Service ์ƒํƒœ๋ฅผSnapshotํ•˜์—ฌ diff๋ฅผ ์ˆ˜ํ–‰

  3. ์ƒˆ๋กœ ์ƒ์„ฑ ๋ฐ ๋กœ๋“œ๋œ Driver๋ฅผ ํ™•์ธ

  4. Driver์—์„œ Symbol Name์„ ํŒŒ์‹ฑ

  5. User ๊ถŒํ•œ(Medium Integrity)์œผ๋กœ Handle์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธ

๐Ÿ‡