Black Hat Asia 2014 - Persist It: Using and Abusing Microsoft's Fix It Patches
3,944 views · Published 3 April 2014 · 49:27 · Indexed 20 September 2026
Channel: Black Hat · 2014 · People & Blogs
By: Jon Erickson Microsoft has often used Fix It patches, which are a subset of Application Compatibility Fixes, as a way to stop newly identified active exploitation methods against their products. A common Fix It patch type used to prevent exploitation is the previously undocumented In Memory Fix It. This research first focuses on analyzing these in-memory patches. By extracting information from them researchers are able to better understand the vulnerabilities that Microsoft intended to patch. The research then focuses on reverse engineering the patches and using this information to provide the ability to create patches which can be used to maintain persistence on a system.
More from this channel
-
1:00:09
Black Hat USA 2000 - Advanced Windows NT/2K Security (II)
-
1:25:19
Black Hat USA 2003 - The Law of Vulnerabilities
-
58:34
Black Hat USA 2012 - A Stitch in Time Saves Nine: A Case of Multiple Operating System Vulnerability
-
1:01:51
Black Hat USA 2005 - Rogue Squadron: Evil Twins, 802.11intel, Radical RADIUS, & Weaponry for Windows
-
50:45
Black Hat USA 2012 - The Info Leak Era on Software Exploitation
-
1:19:53
Black Hat USA 2002 - Security Aspects in Java Bytecode Engineering
-
29:49
Android FakeID Vulnerability Walkthrough
-
28:11
Resurrecting The Read_Logs Permission on Samsung Devices