Bochspwn Reloaded: Detecting Kernel Memory Disclosure with x86 Emulation and Taint Tracking

4,936 views · Published 21 November 2017 · 53:49 · Indexed 20 September 2026

Channel: Black Hat · 2017 · Travel & Events

Watch on YouTube

In kernel-mode, buffer overflows and similar memory corruption issues in the internal logic are usually self-evident and can be detected with a number of static and dynamic approaches. On the contrary, flaws directly related to interactions with user-mode clients tend to be more subtle, and can survive unnoticed for many years, while still providing primitives similar to the classic bugs. 

By Mateusz Jurczyk

Full Abstract & Presentation Materials: 
https://www.blackhat.com/us-17/briefings.html#bochspwn-reloaded-detecting-kernel-memory-disclosure-with-x86-emulation-and-taint-tracking

More from this channel