当前位置:首页 > 报告详情

WorstFit:揭开 Windows ANSI 中隐藏的 Transformers!.pdf

上传人: 竿*** 编号:981556 2025-11-29 147页 7.35MB

1、BestFitUnveiling Hidden Transformers in Windows ANSI!Orange Tsai Splitline HuangWorstorstOne Day,I Hacked into a BankMade-up story;)$14.50 SET balance=$8$8 DEVCOREDEVCORE Research TeamOrange TsaiSplitline Huang How Windows handles Unicode?貓咪.TXTUCS-2UTF-16UTF-8Evolution of Encoding in MS WindowsSinc

2、e Windows 9xSince Windows 2000(Obsolete)Since May,2019ANSIWindows Code pagesSince NT 3.1Windows internal data stores in this way(Beta)UCS-2UTF-16UTF-8Evolution of Unicode in MS WindowsSince Windows 9xSince Windows 2000Since May,2019ANSIWindows Code pagesSince Windows NTWindows internal data stores i

3、n this way(Obsolete)(Beta)typedef wchar_t WCHAR;UTF-16LEFile NameCommand LineWindows Registry Environment VariableConsole Input(more)typedef wchar_t WCHAR;File NameCommand LineWindows Registry Environment VariableConsole Input(more)int main(int argc,char*argv,char*envp)UTF-16LEtypedef wchar_t WCHAR;

4、File NameCommand LineWindows Registry Environment VariableConsole Input(more)UTF-16LEUCS-2UTF-16UTF-8Since Windows 9x(Obsolete)Since Windows 2000Since May,2019ANSIWindows Code pagesSince NT 3.5GetEnvironmentVariableA Single byte/ANSIGetEnvironmentVariableW Wide char/UnicodeWindows OSHello48 00 65 00

5、 6c 00 6c 00 6f 00On Windows code page 1252(Latin-1)UTF-16GetEnvironmentVariableWWCHAR*env=UTF-16Hello48 00 65 00 6c 00 6c 00 6f 00Windows OSHello48 00 65 00 6c 00 6c 00 6f 00On Windows code page 1252(Latin-1)UTF-16GetEnvironmentVariableAANSIRtlUnicodeStringToAnsiStringchar*env=Hello48656c6c6fWindow

6、s OSOn Windows code page 1252(Latin-1)UTF-16GetEnvironmentVariableAANSIRtlUnicodeStringToAnsiStringv76p70737=3d838char*env=1a 22 c0 03 77 20 64 22 1e 22Bestfit!Windows OSOn Windows code page 1252(Latin-1)UTF-16GetEnvironmentVariableAANSIRtlUnicodeStringToAnsiStringv76p70737=3d838char*env=1a 22 c0 03

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据标记内容,全文主要探讨了Windows ANSI API中的安全漏洞,特别是“Bestfit”机制导致的Unicode到ANSI字符串转换问题。以下是关键点: 1. Windows ANSI API存在安全陷阱,导致Unicode字符串转换时可能产生安全漏洞。 2. “Bestfit”机制在转换过程中没有固定公式,可能导致不同代码页映射不一致。 3. CVE-2024-4577是一个利用此机制进行远程代码执行(RCE)的漏洞。 4. 许多开源项目,如tar、curl、wget等,因未正确处理Unicode到ANSI转换而存在安全风险。 5. 建议用户将系统语言切换到UTF-8,开发者尽可能使用宽字符Windows API来避免此类漏洞。
**Windows编码漏洞揭秘** Windows编码陷阱** Windows安全风险解析**
客服
商务合作
小程序
服务号
折叠