diff --git a/README.md b/README.md index e6c36da..e7874df 100644 --- a/README.md +++ b/README.md @@ -15,7 +15,7 @@ This repository aims to provide functioning code that demonstrated usage of vari |[HMValidateHandle](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/HMValidateHandle/HMValidateHandle/HMValidateHandle.cpp) |![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)|![](icons/tick.png)| ##Caveats -The Descriptor Table pointer leak will work on a standard Windows 10 machine but a Windows 10 Enterprise machine with HyperV enabled will trap on the sidt/sgdt instructions thanks to Intel Non-Privileged Instruction Execution Prevention (NPIEP) and return false values (see: [https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf](https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf), Windows Kernel 64-bit ASLR Improvements). +The Descriptor Table pointer leak will work on a standard Windows 10 (or possibly 8.1: https://twitter.com/JosephBialek/status/768954635570679808) machine but a Windows 10 Enterprise machine with HyperV enabled will trap on the sidt/sgdt instructions thanks to Intel Non-Privileged Instruction Execution Prevention (NPIEP) and return false values (see: [https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf](https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf), Windows Kernel 64-bit ASLR Improvements). ##Attributions I have referenced where I read about a technique and where specific structs etc have come from in the code, however these may not be the true original sources of the information :) A lot of the function prototypes and struct definitions are taken from [ReactOS](https://www.reactos.org/).