Zum Inhalt springen

0xa000 · Bereich

Windows-Exploitation

Windows teilt die Grundlagen der Speicherkorruption mit Linux, hat aber seine eigene Exploitation-Geschichte und eigene Abwehr. Dieser Bereich behandelt die Technik, die Windows berühmt machte — einen Structured Exception Handler überschreiben, um den Kontrollfluss zu kapern — dann die DEP-Umgehung per ROP-Kette, die VirtualProtect aufruft, und die Kontrollfluss-Mitigationen, die auf jede antworteten: SafeSEH und SEHOP, ASLR, Control Flow Guard und zuletzt Hardware-CET. Die Beispiele bauen ein absichtlich verwundbares Programm in einer Wegwerf-Windows-VM.

Leitfäden in diesem Bereich

  1. Windows keeps a linked list of exception handlers on the stack. Overflow into one, point it at a pop-pop-ret, trigger a fault, and control is yours — the technique Windows made famous.

  2. DEP makes stack shellcode unrunnable, so a Windows ROP chain calls VirtualProtect to mark the shellcode region executable, then jumps to it. Build it with mona, then see ASLR and CFG respond.

  3. How SafeSEH, SEHOP, ASLR, Control Flow Guard and hardware CET each close a Windows exploitation technique — what they check, how to enable them, and their limits.

Leitfäden erscheinen zuerst auf Englisch. Übersetzungen folgen.

Weitere Bereiche