No video

Linux Kernel Exploitation with Maxwell Bland

  Рет қаралды 85

SIGPwny

SIGPwny

Күн бұрын

Join Maxwell Bland, recent PhD graduate from UIUC, for a talk about contemporary Linux kernel exploitation strategies!
The last five years have introduced extensive new subsystems to common Linux kernel downstreams, such as BPF, EROFS filesystems, and self-patching code. These new systems have introduced novel, unsolved threat vectors for the Linux kernels, and exploit chains targeting these subsystems are further exacerbated by existing exploits techniques targeting writable resources such as file operations structures, TRNG device pointers, and MMIO registers. While point-patches can and do mitigate a number of attack vectors, these do not systematically harden kernel maintenance procedures and infrastructure, resulting in the continued publicization of new exploits leveraging old techniques. This presentation dissects the anatomy of three recent high-profile kernel exploits and their mitigations, then rediscovers a number of memory management assumptions and microarchitecture-level kernel modifications (e.g. BPF-CFI) necessary to guarantee kernel security moving into the next decade. It ends by discussing a number of emerging exploit paths, steps for effective Linux kernel patch submissions and testing, and larger issues regarding the incorporation of patches into downstream projects like Android.
Meeting slides: sigpwny.com/me...

Пікірлер
SP2024 Week 10: AI Hacking (2024-03-28)
29:02
SIGPwny
Рет қаралды 101
The Tragedy of systemd
47:18
linux.conf.au
Рет қаралды 1,1 МЛН
The Joker saves Harley Quinn from drowning!#joker  #shorts
00:34
Untitled Joker
Рет қаралды 72 МЛН
Кадр сыртындағы қызықтар | Келінжан
00:16
Вы чего бл….🤣🤣🙏🏽🙏🏽🙏🏽
00:18
女孩妒忌小丑女? #小丑#shorts
00:34
好人小丑
Рет қаралды 81 МЛН
FA2023 Week 11: Antivirus and EDR Evasion (2023-11-12)
53:06
SIGPwny
Рет қаралды 1,1 М.
No One Wants To Be A Network Engineer Anymore
21:44
Gestalt IT
Рет қаралды 78 М.
WEBINAR VoLTE An in depth analysis
1:06:50
SecurityGen
Рет қаралды 142
Ranking All 108 GNU/Linux Coreutils Commands - GNU Coreutils Tier List
27:45
RobertElderSoftware
Рет қаралды 27 М.
Vim Tips I Wish I Knew Earlier
23:00
Sebastian Daschner
Рет қаралды 58 М.
Everything I Want to Do Is Illegal!
11:54
Luke Smith
Рет қаралды 143 М.
The Magic of RISC-V Vector Processing
16:56
LaurieWired
Рет қаралды 286 М.
Visualizing memory layout of Rust's data types
39:39
Sreekanth
Рет қаралды 13 М.
SP2024 Week 09: Block and Stream Ciphers (2024-03-21)
1:11:07
The Joker saves Harley Quinn from drowning!#joker  #shorts
00:34
Untitled Joker
Рет қаралды 72 МЛН