Overview:
Over the past several years, Microsoft has implemented a number of memory protection mechanisms with the goal of preventing the reliable exploitation of common software vulnerabilities on the Windows platform. Protection mechanisms such as GS, SafeSEH, DEP and ASLR complicate the exploitation of many memory corruption vulnerabilities and at first sight present an insurmountable obstacle for exploit developers.
This talk aims to present exploitation methodologies against this increasingly complex target. We will demonstrate how the inherent design limitations of the protection mechanisms in Windows Vista make them ineffective for preventing the exploitation of memory corruption vulnerabilities in browsers and other client applications.
Each of the aforementioned protections will be briefly introduced and its design limitations will be discussed. We will present a variety of techniques that can be used to bypass the protections and achieve reliable remote code execution in many different circumstances. Finally, we will discuss what Microsoft can do to increase the effectiveness of the memory protections at the expense of annoying Vista users even more.
Black Hat DC 2009
Hyatt Regency Crystal City
Arlington, VA
Training February 16-17
Briefings February 18-19
Black Hat Training DC 2009 information is online now.
Please check out Black Hat DC 2009's sponsors.
Black Hat DC 2009 Call for Papers is open now and will close January 1, 2009. We anticpate that final selections will be made by January 15, 2009.
Black Hat Europe 2009
Moevenpick City Center
Amsterdam, NL
Training April 14-15
Briefings April 16-17
Black Hat Training Europe 2009 information is online now
Please check out Black Hat Europe 2009's sponsors.
Black Hat Europe 2009 Call for Papers is open now and will close February 1, 2009. We anticpate that final selections will be made by February 15, 2009.
Black Hat Social
Black Hat Webcasts
LinkedIn
Flickr
Twitter
Delicious