Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

Reverse Engineering and Bug Hunting on KMDF Drivers - Enrique Nissim at 44CON 2018

Автор: 44CON Information Security Conference

Загружено: 2019-04-15

Просмотров: 2728

Описание:

Reverse Engineering and Bug Hunting on KMDF Drivers - Enrique Nissim at 44CON 2018

Numerous technical articles, presentations, and even books exists about reverse engineering the Windows Driver Model (WDM) for purposes that vary from simply understanding how a specific driver works, to malware analysis and bug hunting. On the other hand, Microsoft has been providing the Kernel Mode Driver Framework (KMDF) for quite a while and we now see more and more drivers shifting to this framework instead of interacting directly with the OS like in the old WDM times. Yet, there is close to no information on how to approach this model from a reverse engineering and offensive standpoint.
In this presentation, I will first do a quick recap on WDM drivers, its common structures, and how to identify its entry points. Then I’ll introduce KMDF with all its relevant functions for reverse engineering through a set of case-studies. I’ll describe how to interact with a KMDF device object through SetupDI api and how to find and analyze the different IO queues dispatch routines. Does the framework actually enhances security? We’ll come to a conclusion after revealing some major vendor implementation problems.

Armed with this knowledge, you will be able to run your own bug hunting session over any KMDF driver.

For more from 44CON and tickets visit 44CON Website: https://44con.com

--=== Contact ===--
YouTube:    / 44contv  
Website: https://44con.com
Twitter:   / 44con  
LinkedIn:   / 44con-3886577  
Facebook:   / 44con  

--=== Music Credits ===--
Island - by MBB:   / mbbofficial   (  / mbbmusic  )
Grind - by Andrew Huang - YouTube Music Library

Reverse Engineering and Bug Hunting on KMDF Drivers - Enrique Nissim at 44CON 2018

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

Kill All Humans... Bugs! - Philippe Arteau at 44CON 2018

Kill All Humans... Bugs! - Philippe Arteau at 44CON 2018

[stream] USB: Reverse Engineering and Writing Drivers

[stream] USB: Reverse Engineering and Writing Drivers

Jesse Michael - Get Off the Kernel if You Can't Drive - DEF CON 27 Conference

Jesse Michael - Get Off the Kernel if You Can't Drive - DEF CON 27 Conference

Windows Device Drivers Internals and some Reversing

Windows Device Drivers Internals and some Reversing

Conversation with Elon Musk | World Economic Forum Annual Meeting 2026

Conversation with Elon Musk | World Economic Forum Annual Meeting 2026

Музыка для работы - Deep Focus Mix для программирования, кодирования

Музыка для работы - Deep Focus Mix для программирования, кодирования

Using the Windows Driver Framework to build better drivers

Using the Windows Driver Framework to build better drivers

Luke Jennings - Threat hunting in the browser

Luke Jennings - Threat hunting in the browser

Зеленского накормили этим

Зеленского накормили этим

Ilja van Sprundel: Windows drivers attack surface

Ilja van Sprundel: Windows drivers attack surface

John McIntosh - ghidriff

John McIntosh - ghidriff

DEF CON 31 — Физические атаки на смартфоны — Кристофер Уэйд

DEF CON 31 — Физические атаки на смартфоны — Кристофер Уэйд

Орешник это модернизированный Рубеж? И как украинцы узнали об ударе 9 января заранее?

Орешник это модернизированный Рубеж? И как украинцы узнали об ударе 9 января заранее?

[2026] Feeling Good Mix - English Deep House, Vocal House, Nu Disco | Emotional / Intimate Mood

[2026] Feeling Good Mix - English Deep House, Vocal House, Nu Disco | Emotional / Intimate Mood

Kubernetes — Простым Языком на Понятном Примере

Kubernetes — Простым Языком на Понятном Примере

4 Hours Chopin for Studying, Concentration & Relaxation

4 Hours Chopin for Studying, Concentration & Relaxation

Reverse Engineering Simple Windows Driver

Reverse Engineering Simple Windows Driver

(Mis)adventures with Copilot+: Attacking and Exploiting Windows NPU Drivers

(Mis)adventures with Copilot+: Attacking and Exploiting Windows NPU Drivers

DEF CON 31 - Still Vulnerable Out of the Box - Ryan Johnson, Mohamed Elsabagh, Angelos Stavrou

DEF CON 31 - Still Vulnerable Out of the Box - Ryan Johnson, Mohamed Elsabagh, Angelos Stavrou

VULNERABLE Kernel Drivers for Security Research

VULNERABLE Kernel Drivers for Security Research

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: infodtube@gmail.com