add NPIEP caveat

This commit is contained in:
Sam Brown
2017-03-01 23:19:34 +00:00
parent 2f0e902fe2
commit 8d2e7df2a5
+1 -1
View File
@@ -15,7 +15,7 @@ This repository aims to provide functioning code that demonstrated usage of vari
|[HMValidateHandle](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/HMValidateHandle/HMValidateHandle/HMValidateHandle.cpp) |![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)|
##Caveats
The Descriptor Table pointer leak will work on a standard Windows 10 machine but a Windows 10 Enterprise machine with HyperV enabled will trap on the sidt/sgdt instructions thanks to Intel Non-Privileged Instruction Execution Prevention (NPIEP) and return false values (see: [https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf](https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf), Windows Kernel 64-bit ASLR Improvements).
The Descriptor Table pointer leak will work on a standard Windows 10 (or possibly 8.1: https://twitter.com/JosephBialek/status/768954635570679808) machine but a Windows 10 Enterprise machine with HyperV enabled will trap on the sidt/sgdt instructions thanks to Intel Non-Privileged Instruction Execution Prevention (NPIEP) and return false values (see: [https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf](https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf), Windows Kernel 64-bit ASLR Improvements).
##Attributions
I have referenced where I read about a technique and where specific structs etc have come from in the code, however these may not be the true original sources of the information :)
A lot of the function prototypes and struct definitions are taken from [ReactOS](https://www.reactos.org/).