<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Defeating Windows Driver Signature Enforcement #2: CSRSS and thread desktops</title>
	<atom:link href="http://j00ru.vexillium.org/?feed=rss2&#038;p=1393" rel="self" type="application/rss+xml" />
	<link>http://j00ru.vexillium.org/?p=1393</link>
	<description>Coding, reverse engineering, OS internals covered one more time</description>
	<lastBuildDate>Fri, 14 Jun 2013 08:52:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Old Click &#187; First cracks appear in Windows RT&#039;s locked-down desktop</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-109842</link>
		<dc:creator>Old Click &#187; First cracks appear in Windows RT&#039;s locked-down desktop</dc:creator>
		<pubDate>Tue, 08 Jan 2013 19:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-109842</guid>
		<description><![CDATA[[...] such smirch was documented by Google-employed certainty researcher Mateusz &#8220;j00ru&#8221; Jurczyk in Nov 2011. Certain [...]]]></description>
		<content:encoded><![CDATA[<p>[...] such smirch was documented by Google-employed certainty researcher Mateusz &#8220;j00ru&#8221; Jurczyk in Nov 2011. Certain [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Circumventing Windows RT&#8217;s Code Integrity Mechanism &#171; On the Surface of Security</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-107655</link>
		<dc:creator>Circumventing Windows RT&#8217;s Code Integrity Mechanism &#171; On the Surface of Security</dc:creator>
		<pubDate>Sun, 06 Jan 2013 02:09:35 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-107655</guid>
		<description><![CDATA[[...] j00ru//vx tech blog: Defeating Windows Driver Signature Enforcement #2: CSRSS and thread desktops [2] Visual Studio 2012 Remote Tools [3] Using the complete Windows API in store apps (mamaich at [...]]]></description>
		<content:encoded><![CDATA[<p>[...] j00ru//vx tech blog: Defeating Windows Driver Signature Enforcement #2: CSRSS and thread desktops [2] Visual Studio 2012 Remote Tools [3] Using the complete Windows API in store apps (mamaich at [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yuhong Bao</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-83894</link>
		<dc:creator>Yuhong Bao</dc:creator>
		<pubDate>Tue, 11 Dec 2012 04:06:53 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-83894</guid>
		<description><![CDATA[&quot;Perhaps it’s the largest source of local and remote vulnerabilities in the Windows kernel ever.&quot;
The funny thing is when NT 4.0 was released back in 1996, WinFrame already existed based on NT 3.51 with *per-session* CSRSS, but NT4 TSE was not released until 1998.]]></description>
		<content:encoded><![CDATA[<p>&#8220;Perhaps it’s the largest source of local and remote vulnerabilities in the Windows kernel ever.&#8221;<br />
The funny thing is when NT 4.0 was released back in 1996, WinFrame already existed based on NT 3.51 with *per-session* CSRSS, but NT4 TSE was not released until 1998.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Defeating Windows Driver Signature Enforcement #3: The Ultimate Encounter &#124; j00ru//vx tech blog</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-83402</link>
		<dc:creator>Defeating Windows Driver Signature Enforcement #3: The Ultimate Encounter &#124; j00ru//vx tech blog</dc:creator>
		<pubDate>Mon, 10 Dec 2012 09:04:13 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-83402</guid>
		<description><![CDATA[[...] with the OS in the default configuration to trigger Blue Screens of Death from user-mode, and implementing a complete bypass of the functionality by using a design flaw in how the CSRSS subsystem interacts with the win32k.sys kernel module, I am [...]]]></description>
		<content:encoded><![CDATA[<p>[...] with the OS in the default configuration to trigger Blue Screens of Death from user-mode, and implementing a complete bypass of the functionality by using a design flaw in how the CSRSS subsystem interacts with the win32k.sys kernel module, I am [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marsh mellow</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-67965</link>
		<dc:creator>marsh mellow</dc:creator>
		<pubDate>Thu, 15 Nov 2012 18:13:06 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-67965</guid>
		<description><![CDATA[Well the sipset from ObDereferenceObject fail to match a nice msdn page.

Why put disassembly thats incomplete when people can read plain english.

http://msdn.microsoft.com/en-us/library/windows/hardware/ff557724(v=vs.85).aspx]]></description>
		<content:encoded><![CDATA[<p>Well the sipset from ObDereferenceObject fail to match a nice msdn page.</p>
<p>Why put disassembly thats incomplete when people can read plain english.</p>
<p><a href="http://msdn.microsoft.com/en-us/library/windows/hardware/ff557724(v=vs.85)" rel="nofollow">http://msdn.microsoft.com/en-us/library/windows/hardware/ff557724(v=vs.85)</a>.aspx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hello</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-67824</link>
		<dc:creator>hello</dc:creator>
		<pubDate>Thu, 15 Nov 2012 13:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-67824</guid>
		<description><![CDATA[I mean when I exploit success(aka. nt!g_cienabled has been set to 0), then when I load a unsigned driver, the &quot;Program Compatibility Assistant&quot; dialog appear and says &quot;Windows requires a digitally signed driver...&quot;, of course the driver loaded successfully. but I don&#039;t want the PCA dialog show.]]></description>
		<content:encoded><![CDATA[<p>I mean when I exploit success(aka. nt!g_cienabled has been set to 0), then when I load a unsigned driver, the &#8220;Program Compatibility Assistant&#8221; dialog appear and says &#8220;Windows requires a digitally signed driver&#8230;&#8221;, of course the driver loaded successfully. but I don&#8217;t want the PCA dialog show.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: j00ru</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-67806</link>
		<dc:creator>j00ru</dc:creator>
		<pubDate>Thu, 15 Nov 2012 12:43:44 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-67806</guid>
		<description><![CDATA[@marsh mellow: really, I think it&#039;s pretty clear what the listing shows (four breaks in random intervals during the process of decrementing the value by one 256 times) based on the context, and let&#039;s stop there.]]></description>
		<content:encoded><![CDATA[<p>@marsh mellow: really, I think it&#8217;s pretty clear what the listing shows (four breaks in random intervals during the process of decrementing the value by one 256 times) based on the context, and let&#8217;s stop there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marsh mellow</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-67803</link>
		<dc:creator>marsh mellow</dc:creator>
		<pubDate>Thu, 15 Nov 2012 12:38:09 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-67803</guid>
		<description><![CDATA[&quot;None of the other readers complained&quot; ... well im not complaining im just highlighting the fastforward assumption without details.

I understand you might not want people to recreate it right off the shelf, but if i read something that disclose and issue why not detail it correctly.

And last time i tried to compile imagination, i couldn&#039;t, lack of memory.]]></description>
		<content:encoded><![CDATA[<p>&#8220;None of the other readers complained&#8221; &#8230; well im not complaining im just highlighting the fastforward assumption without details.</p>
<p>I understand you might not want people to recreate it right off the shelf, but if i read something that disclose and issue why not detail it correctly.</p>
<p>And last time i tried to compile imagination, i couldn&#8217;t, lack of memory.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: j00ru</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-67766</link>
		<dc:creator>j00ru</dc:creator>
		<pubDate>Thu, 15 Nov 2012 11:06:23 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-67766</guid>
		<description><![CDATA[@tobi: erm... I don&#039;t think scanning through W2k kernel sources is by any means legal unless you&#039;re a Microsoft employee. Anyway, it&#039;s true that win32k.sys is intensely messy and there&#039;s a lot of fishy action going on there. Perhaps it&#039;s the largest source of local and remote vulnerabilities in the Windows kernel ever. Looking forward to your reporting some of them ;)

@omeg: hehe ;-)

@marsh mellow: maybe it&#039;s high time to get some imagination? None of the other readers complained.

@hello: not sure if I understand correctly, but I assume that you&#039;re referring to the ability to load unsigned drivers while the system is in debug mode (i.e. with windbg attached remotely). Have you tried loading a driver with remote debugging disabled?]]></description>
		<content:encoded><![CDATA[<p>@tobi: erm&#8230; I don&#8217;t think scanning through W2k kernel sources is by any means legal unless you&#8217;re a Microsoft employee. Anyway, it&#8217;s true that win32k.sys is intensely messy and there&#8217;s a lot of fishy action going on there. Perhaps it&#8217;s the largest source of local and remote vulnerabilities in the Windows kernel ever. Looking forward to your reporting some of them ;)</p>
<p>@omeg: hehe ;-)</p>
<p>@marsh mellow: maybe it&#8217;s high time to get some imagination? None of the other readers complained.</p>
<p>@hello: not sure if I understand correctly, but I assume that you&#8217;re referring to the ability to load unsigned drivers while the system is in debug mode (i.e. with windbg attached remotely). Have you tried loading a driver with remote debugging disabled?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hello</title>
		<link>http://j00ru.vexillium.org/?p=1393&#038;cpage=1#comment-67760</link>
		<dc:creator>hello</dc:creator>
		<pubDate>Thu, 15 Nov 2012 10:53:15 +0000</pubDate>
		<guid isPermaLink="false">http://j00ru.vexillium.org/?p=1393#comment-67760</guid>
		<description><![CDATA[when load driver,the Program Compatibility Assistant dialog show,but the driver has loaded success. So why the PCA dialog show and how to fuck this?]]></description>
		<content:encoded><![CDATA[<p>when load driver,the Program Compatibility Assistant dialog show,but the driver has loaded success. So why the PCA dialog show and how to fuck this?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
