<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>j00ru//vx tech blog</title>
	<link>http://j00ru.vexillium.org</link>
	<description>Coding, reverse engineering, OS internals covered one more time</description>
	<lastBuildDate>Sun, 05 Sep 2010 23:06:59 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0.1" -->

	<item>
		<title>Kernel exploitation &#8211; r0 to r3 transitions via KeUserModeCallback</title>
		<description><![CDATA[Hey there! I have recently came across (well, not entirely by myself... cheers Nahuel!) a fairly (un)common problem related to performing ring0-to-ring3 transitions, after a successful kernel vulnerability exploitation. As I have managed to come up with a bunch of possible solutions, and even write exemplary code for some of these, today I would like [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=614</link>
			</item>
	<item>
		<title>Windows CSRSS Write Up: Inter-process Communication (part 2/3)</title>
		<description><![CDATA[A quick beginning note: My friend d0c_s4vage has created a technical blog and posted his first text just a few days ago. The post entry covers a recent, critical libpng vulnerability discovered by this guy; the interesting thing is that, among others, the latest Firefox and Chrome versions were vulnerable. Feel free to take a [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=527</link>
			</item>
	<item>
		<title>Blog customization, old PHP advisories</title>
		<description><![CDATA[Hey there! Today, I would like to post a less-technical text, discussing two issues I have recently came across, or been busy with; don't worry though, as CSRSS Write-Up: IPC (part 2/3) is on the way. The first matter is about recent changes applied to the blog appearance and functionality, while the latter regards the [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=563</link>
			</item>
	<item>
		<title>Windows CSRSS Write Up: Inter-process Communication (part 1/3)</title>
		<description><![CDATA[In the second post of the Windows CSRSS Write Up series, I would like to explain how the practical communication between the Windows Subsystem and user's process takes place under the hood. Due to the fact that some major improvements have been introduced in Windows Vista and later, the entire article is split into two [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=502</link>
			</item>
	<item>
		<title>Windows CSRSS Write Up: the basics (part 1/1)</title>
		<description><![CDATA[NOTE: The following post entry opens a series of CSRSS-oriented articles, aiming at describing the uncovered CSRSS mechanism internals, present in the Windows OS for more than fifteen years now. Although some great research has already been carried out by a few curious guys (check out the references), no thorough case study is available until [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=492</link>
			</item>
	<item>
		<title>Attacking the Host via Remote Kernel Debugger (Virtual Machines)</title>
		<description><![CDATA[NOTE: This post is highly related to the research performed by Alex Ionescu. He is going to present the results of his work on the RECON2010 conference, during his Debugger-based Target-to-Host Cross-System Attacks speech. As it turns out, me and Alex have been working on the same subject concurrently - while I have only managed [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=405</link>
			</item>
	<item>
		<title>A quick insight into the Driver Signature Enforcement</title>
		<description><![CDATA[Hey! I have recently had some fun playing around with driver signing on Windows x64, and so I like to share some matters that have came into my head Therefore, let me briefly describe some internal mechanisms lying behind well known Driver Signature Enforcement, a significant part of the Code Integrity feature introduced by Microsoft [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=377</link>
			</item>
	<item>
		<title>CONFidence 2010 is over</title>
		<description><![CDATA[One of the biggest (best ) IT security-oriented conferences in Poland finished three days ago, in the wednesday evening. In the very first place, I would like to congratulate all the organisers, for their decision on where the event should be held, as well as how it should look like - during these two days, [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=363</link>
			</item>
	<item>
		<title>Windows CSRSS cross-version API Table</title>
		<description><![CDATA[Hello! It seems like half a year has passed since I published the Win32k.SYS system call table list on the net. During this time (well, it didn't take so long ) I managed to gather enough information to release yet another API list - this time, concerning an user-mode application - CSRSS (Client/Server Runtime SubSystem). [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=349</link>
			</item>
	<item>
		<title>Windows Kernel Vulnerabilities continued &#8211; details</title>
		<description><![CDATA[And so it happened ;&#62; As I've written in this post, Gynvael Coldwind has just finished speaking about recent Windows Kernel Vulnerabilities on the Hack In The Box Dubai conference, taking place today. Unfortunately, because of the European air communication being disabled these days, the presentation was held remotely - one way or another, it [...]]]></description>
		<link>http://j00ru.vexillium.org/?p=343</link>
			</item>
</channel>
</rss>
