Search found 12 matches

by Orkblutt
Thu May 18, 2017 10:26 am
Forum: User-Mode Development
Topic: ETW discussion
Replies: 0
Views: 11897

ETW discussion

Hi all, I am playing with Event Trace for Windows, ETW, to trace down some kernel events like files, disk IO and network. ( https://msdn.microsoft.com/fr-fr/library/windows/desktop/bb968803(v=vs.85).aspx ) No problem to get realtime events from userland but I try to achieve reboot persistency and tr...
by Orkblutt
Tue May 16, 2017 9:40 am
Forum: Malware
Topic: WanaCrypt0r 2.0
Replies: 15
Views: 26430

Re: WanaCrypt0r 2.0

@EP_X0FF: +1 :(
by Orkblutt
Tue Sep 28, 2010 7:11 am
Forum: Kernel-Mode Development
Topic: TRON & SMP issue
Replies: 17
Views: 22024

Re: TRON & SMP issue

Hey Alex,

i forgot Ivanlef0u's blog... Really nice resources in there.

Gabben, can you say me more about that app? Did you try to hook SwapContext to avoid TLB flushing?

Regards,

Orky
by Orkblutt
Sun Sep 26, 2010 10:03 pm
Forum: Kernel-Mode Development
Topic: TRON & SMP issue
Replies: 17
Views: 22024

Re: TRON & SMP issue

here a an interesting thread on the subject:
http://www.rootkit.com/board.php?did=pr ... 0&lastx=15
Where are you Bugcheck... I miss you!! ;)
by Orkblutt
Fri Sep 24, 2010 8:28 am
Forum: Kernel-Mode Development
Topic: TRON & SMP issue
Replies: 17
Views: 22024

Re: TRON & SMP issue

Thanks Alex! Very interesting stuffs here.

Have now to resolve the PAE issue... :)

Regards,

Orkblutt
by Orkblutt
Mon Sep 20, 2010 10:08 am
Forum: Kernel-Mode Development
Topic: TRON & SMP issue
Replies: 17
Views: 22024

Re: TRON & SMP issue

Why don't you give it a go and try it?
In fact I am since 2 weeks and it looks to work fine with just some minor modifications. I was wondering there is something I couldn't see needing a major rewrite to be SMP compatible. Looks like I was wrong.
Anyway, thanks.

Orkblutt
by Orkblutt
Sun Sep 19, 2010 9:25 am
Forum: Kernel-Mode Development
Topic: TRON & SMP issue
Replies: 17
Views: 22024

Re: TRON & SMP issue

Hi DBS, When writing to usermode memory in order to delete the Dll-Entries from the Ldr-Lists, he simply delays all interrupts with CLI on the actual CPU, which is unsafe for multiprocessor systems. Yes... I noticed this point. In fact I'm not interested at all by this part. The only interesting par...
by Orkblutt
Fri Sep 17, 2010 7:51 pm
Forum: Kernel-Mode Development
Topic: TRON & SMP issue
Replies: 17
Views: 22024

Re: TRON & SMP issue

Hi Alex, You can find the src and the slide here: http://www.openrce.org/downloads/details/234/ It's in fact an improvment of the "Shadow walker" rootkit. ( http://www.blackhat.com/presentations/bh-jp-05/bh-jp-05-sparks-butler.pdf ) One of the knowed issue to this thechnic is to not support SMP syst...
by Orkblutt
Thu Sep 16, 2010 3:36 pm
Forum: Kernel-Mode Development
Topic: TRON & SMP issue
Replies: 17
Views: 22024

TRON & SMP issue

Hi,

I'm currently studying Tron's code... I'm not sure to understand why this technic can't be used on SMP systems without a major rewrite.
Someone can give me more information about this issue?

Regards,

Orkblutt