Bochspwn Reloaded: Detecting Kernel Memory Disclosure with x86 Emulation and Taint Tracking
4,936 views · Published 21 November 2017 · 53:49 · Indexed 20 September 2026
Channel: Black Hat · 2017 · Travel & Events
In kernel-mode, buffer overflows and similar memory corruption issues in the internal logic are usually self-evident and can be detected with a number of static and dynamic approaches. On the contrary, flaws directly related to interactions with user-mode clients tend to be more subtle, and can survive unnoticed for many years, while still providing primitives similar to the classic bugs. By Mateusz Jurczyk Full Abstract & Presentation Materials: https://www.blackhat.com/us-17/briefings.html#bochspwn-reloaded-detecting-kernel-memory-disclosure-with-x86-emulation-and-taint-tracking
More from this channel
-
1:00:09
Black Hat USA 2000 - Advanced Windows NT/2K Security (II)
-
1:25:19
Black Hat USA 2003 - The Law of Vulnerabilities
-
58:34
Black Hat USA 2012 - A Stitch in Time Saves Nine: A Case of Multiple Operating System Vulnerability
-
1:01:51
Black Hat USA 2005 - Rogue Squadron: Evil Twins, 802.11intel, Radical RADIUS, & Weaponry for Windows
-
50:45
Black Hat USA 2012 - The Info Leak Era on Software Exploitation
-
1:19:53
Black Hat USA 2002 - Security Aspects in Java Bytecode Engineering
-
49:27
Black Hat Asia 2014 - Persist It: Using and Abusing Microsoft's Fix It Patches
-
29:49
Android FakeID Vulnerability Walkthrough