1) Wrote a while back about "Protecting aginst Pointer Subterfuge". Michael Howard has updated the description of the algorithm used to encode pointers with EncodePointer/EncodeSystemPointer.
2) Previously, I pointed to an article on the Microsoft Driver site that details x64 Kernel Patch Protection. The Windows Vista Security blog has a higher-level description of kernel patching as well as some suggestions for alternatives.
2006-08-22
Some Updates - Protecting against Pointer Subterfuge and Kernel Patch Protection (PatchGuard)
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment