mirror of
https://github.com/sam-b/windows_kernel_address_leaks
synced 2026-08-09 13:07:58 +00:00
descriptor table caveat
This commit is contained in:
@@ -13,7 +13,8 @@ This repository aims to provide functioning code that demonstrated usage of vari
|
||||
|[Descriptor Tables](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/DescriptorTables/DescriptorTables/DescriptorTables.cpp) | | | ||||
|
||||
|
||||
|
||||
|
||||
##Caveats
|
||||
The Descriptor Table pointer leak will work on a standard Windows 10 machine but a Windows 10 Enterprise machine with HyperV enabled will trap on the sidt/sgdt instructions and return false values (see: [https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf](https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf), Windows Kernel 64-bit ASLR Improvements.
|
||||
##Attributions
|
||||
I have referenced where I read about a technique and where specific structs etc have come from in the code, however these may not be the true original sources of the information :)
|
||||
A lot of the function prototypes and struct definitions are taken from [ReactOS](https://www.reactos.org/).
|
||||
|
||||
Reference in New Issue
Block a user