175 Commits

Author SHA1 Message Date
Gonçalo Carvalho b1cc756e55 Fix status value in UaF object allocation functions. As it stands it always returns STATUS_UNSUCCESSFUL even if no error exists (#66) 2025-02-24 17:49:16 +05:30
Milton Valencia ceadb2097b Adding tutorials (wetw0rk) (#67) 2025-02-24 17:47:10 +05:30
Abhishek Kumar Singh 78fdbb43a7 FIX: Spaces in Directory Path (#65) 2025-01-13 21:55:52 +05:30
OctavioGalland 1887af56e1 Explicitly specify sha1 digest algorithm when signing (#63) 2025-01-03 00:31:46 +05:30
Divyanshu | seg_fault 536d271bd7 Fix the sizeof to avoid casting into 64 bit (#59) 2024-09-04 20:39:18 +05:30
HackSys Team b02b6ea3ce FIX: Added new blogposts and discord server invite badge 2023-10-02 13:08:15 +05:30
HackSys Team 5147bed2d2 FIX: Added new blogposts and discord server invite badge 2023-10-02 13:06:46 +05:30
HackSys Team 219b78c2ec FIX: copy_from_user macro already inserts size checks, so use __copy_from_user 2023-08-12 01:01:59 +05:30
HackSys Team 3ecd3e4ed4 FIX: Added HEVD linux screenshots 2023-08-11 16:40:03 +05:30
HackSys Team e8e9d99ef9 FIX: fixed related to SMAP and added test cases to trigger IOCTLs in HEVD for Linux 2023-08-11 16:22:10 +05:30
HackSys Team fee7617094 FIX: Updated copyright information 2023-08-11 12:13:31 +05:30
HackSys Team f7b55c8aae FIX: Added TypeConfusion blog post link 2023-08-11 11:29:39 +05:30
HackSys Team 76b3efab3c FIX: Make the profile links work 2022-12-07 13:53:44 +05:30
HackSys Team 98de2d349b FIX: Github is not parsing LICENSE file correctly 2022-12-07 13:29:20 +05:30
HackSys Team 6bff3d3e7a FIX: Added contributors image in README 2022-12-07 13:27:49 +05:30
HackSys Team 09f3a97b34 FIX: Added local screenshots to avoid breakage on URL changes 2022-12-07 13:18:37 +05:30
HackSys Team 9e6b3ef117 FIX: Updated README 2022-12-07 13:17:07 +05:30
HackSys Team 5bc2bd43cd FIX: Normalized line ending of all files. Changed from CRLF to LF and indent using 4 spaces instead of 1 tab 2022-12-07 13:14:47 +05:30
yardenshafir bdeebe4ab6 Fix handler to increment by 1 instead of 8 (#49)
```(*(PULONG_PTR*)UserPointerToIncrementValue)++; ```
increments by one pointer (so 8) instead of 1. To make this a 1-byte arbitrary increment, making UserPointerToIncrementValue a PCHAR, and incrementing by 1 CHAR.
2022-06-15 15:10:38 +05:30
?̖̣̗̫͙͜ͅ?̕\x02?̨͇̠̲͖̹\x0a?̕w\x04fz\x05uck5?̕?̨͇̠̲͖ a0dc8375f3 Added WriteNull Solution (#47)
Closing #46
2021-12-06 13:23:14 +05:30
HackSys Team a84693e30e Fixed Linux build error which was caused by the last commit bb5e6670f3 2021-09-27 07:42:33 -07:00
HackSys Team bb5e6670f3 Windows on ARM support
- Added build script and updated CMakeLists
- Tracking issue #44
2021-09-27 06:43:29 -07:00
Kristal-g b88ca1171b Added solution references for windows 10 64bit (#43)
Added write-up references for type confusion and StackOverflowGS for windows 10 x64
2021-07-26 20:26:34 +05:30
HackSys Team 3930abbfbf Added Arbitrary Increment in README 2021-07-26 00:05:31 -07:00
HackSys Team acc80985f8 Added Arbitrary Increment Vulnerability. Closes #40 2021-07-26 00:03:49 -07:00
HackSys Team 643f39023b Fixed unprobed buffer issue in SECURE mode. Fixes #42 2021-07-20 03:55:00 -07:00
HackSys Team 7e941cefd6 Fixed format specifiers for size_t 2021-07-20 03:54:04 -07:00
HackSys Team 262884242f Fixed race condition in WriteNULL. Closed pull request #38 2020-08-13 00:40:39 -07:00
HackSys Team 9acd32095f Merge branch 'Shoshkin-bugfix/double-fetch-in-secure-write-null' into master 2020-08-13 00:08:09 -07:00
HackSys Team 34b4433f56 Merge branch 'bugfix/double-fetch-in-secure-write-null' of https://github.com/Shoshkin/HackSysExtremeVulnerableDriver into Shoshkin-bugfix/double-fetch-in-secure-write-null 2020-08-13 00:07:46 -07:00
hacksysteam b55c50399a Fixed format specifier 2020-08-12 23:36:48 -07:00
hacksysteam 901dfc91ad Fixed format specifier 2020-08-12 23:27:31 -07:00
takubokudori f87cd83b69 Fix Size type in Integer Overflow (#39) 2020-08-13 10:42:30 +05:30
Shai Kvetnoy 81f08d605e Before this fix, there is a double fetch bug in the secure implementation of WriteNULL
it checks the address to write into from the passed usermode buffer, then reads the address again from the buffer
The address inside UserBuffer can be changed (from another thread) right after ProbeForWrite, just before the actual write

The bug is hard to reproduce since the time slot is really small
Easiest way to reproduce is to create a delay after ProbeForWrite, giving enough time for the second thread to change the address.
2020-05-22 05:25:41 +03:00
HackSys Team e6cc0ef60e Updated README 2020-02-20 17:14:44 +05:30
hacksysteam deacc8f059 FIX: Use struct hevd_io to get values from user mode 2020-02-20 17:04:32 +05:30
z\x00^@%00U+2400 8841e80856 Added a new external exploit (#37) 2020-01-06 17:08:39 +05:30
Eric Gaston c53a29cc10 Added break to HEVD_IOCTL_BUFFER_OVERFLOW_STACK case in switch statement (#36) 2019-12-11 12:12:18 +05:30
Abhisek Datta c702a2865d Ported unitialized stack memory vulnerability module to Linux (#35)
* Ported unitialized stack memory vulnerability module to Linux

* Added EOL
2019-11-17 23:05:58 +05:30
hacksysteam c23ed795cd FIX: Changed the status message 2019-10-22 16:48:50 +05:30
hacksysteam 808367b6c0 FIX: UaF should now be easy to exploit on x64 2019-10-22 16:38:11 +05:30
hacksysteam 045bb53828 FIX: Refactored Linux code to look like similar to Windows code in the driver 2019-10-22 13:06:32 +05:30
hacksysteam 1e38c8aa18 FIX: Refactored Linux code to look like similar to Windows code in the driver 2019-10-22 13:04:01 +05:30
hacksysteam a0d5404f44 FIX: Refactored Linux code to look like similar to Windows code in the driver 2019-10-22 12:59:47 +05:30
Abhisek Datta 568b92885b Added Linux port of ArbitraryWrite vulnerability module (#33)
* Added Linux port of ArbitraryWrite vulnerability module

* Fix syntax error for secure build for ArbitraryWrite module

* Fixed API incompatibility issue with kernel 5.x

* Remove redundant x_access_ok check

* Remove goto branching

* Remove temporary Linux build file
2019-10-21 15:08:51 +05:30
hacksysteam 9d236ba1b2 ENHANCEMENT: Updated appveyor config to allow build HEVD for Linux 2019-10-18 17:39:28 +05:30
hacksysteam 16464f149b FIX: changed int to long 2019-10-18 12:29:36 +05:30
hacksysteam 29affe00d1 FIX: Untabify 2019-10-18 12:05:42 +05:30
HackSys Team df149e9300 Merge pull request #31 from abhisek/linux-port-integer-overflow
Ported integer overflow vulnerability module to Linux
2019-10-18 11:19:48 +05:30
HackSys Team dd82b5823a Fixed braces style 2019-10-18 11:17:31 +05:30