today-0day
NotionGithubSiteContact
Korean
Korean
  • Introduction
    • 🚩Windows Driver 0-day Research
    • πŸ«‚Team. 우리 μ˜€λŠ˜λΆ€ν„° 0-day
  • backgrounds
    • Windows Driver
    • Related Works
  • Our Approach
    • κ°œμš”
    • πŸ‡Init Analyzer
    • 😑angr-PT
    • πŸ₯ŒMS Fuzzer
      • Playmaker mode
      • Qemu-nyx
      • Redqueen
      • Multiple Driver Tracing
      • Call Stack Parser
    • How to Use
  • Appendix
    • References
    • Achievments
    • πŸ”—Team page
    • πŸ”—CODE BLUE 2024
Powered by GitBook
On this page
  1. Our Approach
  2. MS Fuzzer

Call Stack Parser

PreviousMultiple Driver TracingNextHow to Use

Last updated 2 months ago

Windows Kernel Debugging 에 μžˆμ–΄μ„œ 뢄석가가 λŠλΌλŠ” 어렀움은 Crashλ°œμƒ μ‹œμ— 컴퓨터λ₯Ό μž¬λΆ€νŒ…ν•˜κΈ° λ•Œλ¬Έμ— λ§Žμ€ μ‹œκ°„μ΄ λ“ λ‹€λŠ” κ²ƒμž…λ‹ˆλ‹€.

λ˜ν•œ 퍼징과정 쀑에 쀑볡 Crash도 μ‘΄μž¬ν•˜μ—¬ 이것을 λΉ λ₯΄κ²Œ νŒλ³„ν•΄λ‚΄λŠ” 것이 ν•„μš”ν•©λ‹ˆλ‹€.

μ΄λŸ¬ν•œ λ¬Έμ œμ μ„ ν•΄κ²°ν•˜κΈ° μœ„ν•΄ μ•„λž˜μ™€ 같이 qemu-nyx에 Hyper Call을 μΆ”κ°€ν•΄ Crashλ°œμƒ μ‹œ Guest OS의 Call Stack을 λ€ν”„ν•΄μ˜¬ 수 μžˆλ„λ‘ ν•˜μ˜€μŠ΅λ‹ˆλ‹€.

πŸ₯Œ