Live data from Hacker News

0x01 – Killing Windows Kernel Mitigations

wetw0rk.github.io

1–10 of 14 posts

Re: 0x01 – Killing Windows Kernel Mitigations

#2
If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now.

We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then?

Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them.

As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have dubbed Violet Phosphorous. I personally have not seen these mitigations bypassed in this manner so I’m claiming it.

To prove its effectiveness, I installed the latest Windows 11 (x64) build (24H2) and successfully elevated my privileges to NT AUTHORITY/SYSTEM.

The king is dead, long live the king!

LONG LIVE THE STACK OVERFLOW!

Re: 0x01 – Killing Windows Kernel Mitigations

#3
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

(This text was originally part of https://news.ycombinator.com/item?id=42353276 but that got killed by HN's software (bad), so I moved it here to the live post.)

Re: 0x01 – Killing Windows Kernel Mitigations

#4
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

Was your test install also fully updated, i.e. is your exploit currently valid?

Re: 0x01 – Killing Windows Kernel Mitigations

#5
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

Super interesting. At one point thought control flow guard + DEP/ASLR was suppose to prevent this stuff, guess it can't be prevented nearly completely by now. Sounds like this took a lot of work to figure out, well done.

Any comment on reporting to Microsoft or perhaps motivation for this research?

Re: 0x01 – Killing Windows Kernel Mitigations

#6
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

Gonna have to give it a proper read-through over the weekend, but this looks like a stellar guide at a glance. Sincere thanks for sharing your work and looking forward to further entries in the series!

Re: 0x01 – Killing Windows Kernel Mitigations

#7
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

Super interesting. At one point thought control flow guard + DEP/ASLR was suppose to prevent this stuff, guess it can't be prevented nearly completely by now. Sounds like this took a lot of work to figure out, well done. Any comment on reporting to Microsoft or perhaps motivation for this research?

So called "post-exploit" mitigations are practically always only hardening, i.e. making subsequent attacks harder (and fewer). Ideally much harder. But if you want an absolutely, provably (within limits, i.e. halting problem etc.) secure system, you have to eliminate bugs that can lead to any exploitable situations beforehand. In this case for example, that would mean no situation existing that could cause a buffer overflow in the first place. Memory-safe languages help for this case.

Obviously this is hard, so post-exploit mitigations will likely continue to still make things harder for attackers for quite a while at least.

Re: 0x01 – Killing Windows Kernel Mitigations

#8
post #4
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

Was your test install also fully updated, i.e. is your exploit currently valid?

Yes the violet phosphorus technique works on the default configuration of the latest build :)

Re: 0x01 – Killing Windows Kernel Mitigations

#9
post #6
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

Gonna have to give it a proper read-through over the weekend, but this looks like a stellar guide at a glance. Sincere thanks for sharing your work and looking forward to further entries in the series!

Thank you!

Re: 0x01 – Killing Windows Kernel Mitigations

#10
post #2

If you’re following my Windows Kernel Exploitation series the time to bypass modern mitigations is now. We’ve learned how to exploit a Stack Overflow in Windows 7 (x86) but what has changed since then? Truthfully a lot, but the core fundamental problem exists and as such we as hackers will always find a way to exploit them. As part of this tutorial, I will be releasing my technique on bypassing SMEP and VBS I have du…

>LONG LIVE THE STACK OVERFLOW!

The mitigation known as Shadow Stack might have something to say here.

Post reply on HN