作者:b2ahex
上一篇edge中拿到任意地址读写,控制返回地址后,下面该触...
阅读全文
作者:b2ahex
感觉好久没有更新过了,记录一下之前在win10环境下的 edge + kernel 漏洞利用过程,最终实现沙箱...
阅读全文
作者:b2ahex
1. 背景介绍
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka “Win32k.sys Elevation of Privilege Vulnerability.”
阅读全文
之前分析过的样本,随便贴点东西上来吧…
by @b2ahex
一、样本信息
样本名称:280836636_37EEC1A29D316ED1E5E766B599DC32A1.bin样本大小: 64,599 字节文件类型:EXE文件病毒名称:HttpBrowser样本MD5: 37eec1a29d316ed1e5e766b599dc32a1样本SHA256:a89c21dd608c51c4bf0323d640f816e464578510389f9edcf04cd34090decc91
阅读全文