Advanced Windows Exploitation.pdf

(340 KB) Pobierz
Advanced Windows Exploitation
Dave Aitel
Immunity, Inc
http://www.immunitysec.com/
Agenda
– What is Immunity?
– Windows for Unix Hackers
– DCE-RPC
– Finding bugs with SPIKE
– MS-SQL
– The shellcode problem
– Heap Overflows
– IIS
– Demos, other fun
Immunity, Inc
New York City based Corporation
7 Months old, privately financed
Information Security Services
Application focus
Protocol Analysis
Training
Cutting Edge Products
CANVAS
BODYGUARD
SPIKE, SPIKE Proxy
Windows for Unix Hackers
Windows
X86
Component
Architecture
Privilege tokens
Threaded
Closed Source
Unix
x86/RISC
Process architecture
User ID
Forked
Open Source
X86
Unaligned address references
Except ESP,EBP which must be word aligned for
internal Windows API calls to work properly
No instruction cache (post 486), register
windows, or other painful RISC idioms
Zgłoś jeśli naruszono regulamin