descriptor table caveat

This commit is contained in:
Sam Brown
2017-02-15 00:47:34 +00:00
parent 8443d6af43
commit 77a9115c91
+2 -1
View File
@@ -13,7 +13,8 @@ This repository aims to provide functioning code that demonstrated usage of vari
|[Descriptor Tables](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/DescriptorTables/DescriptorTables/DescriptorTables.cpp) |![](tick.png) |![](tick.png) |![](tick.png) |![](tick.png)|![](tick.png)|![](tick.png)|
##Caveats
The Descriptor Table pointer leak will work on a standard Windows 10 machine but a Windows 10 Enterprise machine with HyperV enabled will trap on the sidt/sgdt instructions and return false values (see: [https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf](https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf), Windows Kernel 64-bit ASLR Improvements.
##Attributions
I have referenced where I read about a technique and where specific structs etc have come from in the code, however these may not be the true original sources of the information :)
A lot of the function prototypes and struct definitions are taken from [ReactOS](https://www.reactos.org/).