阿隆·列维夫_利用Windows更新的降级攻击.pdf

编号:175507 PDF 87页 1.98MB 下载积分:VIP专享
下载报告请您先登录!

阿隆·列维夫_利用Windows更新的降级攻击.pdf

1、Windows Downdate:Downgrade Attacks Using Windows UpdatesAlon LevievSecurity Researcher SafeBreach22-years-oldSelf-taughtOS internals,reverse engineering and vulnerability researchFormer BJJ world and european championCreator of PoolParty process injection techniquesAgendaResearch BackgroundDowngrade

2、 Attacks Using Windows UpdatesVirtualization-Based Security VulnerabilitiesWindows Update Restoration VulnerabilityClosing RemarksResearch BackgroundWINDOWS DOWNDATEWhat are Downgrade Attacks?Immune SoftwareVulnerable SoftwareDowngrade immunesoftware to vulnerablesoftwareAttackerDowngrade Attacks In

3、-The-Wild BlackLotus UEFI BootkitThe BlackLotus UEFI bootkit employed a downgrade attack to bypass Secure BootThe Secure Boot bypass worked on fully updated Windows 11 machinesCaused a massive panic in the cyber security industrySecure Boot In a NutshellUEFI FirmwareUEFI Boot ManagerWindows Boot Man

4、agerWindows Boot LoaderWindows KernelVerifyEach component in the boot chain must be digitally signedVerifyVerifyVerifyBlackLotus Secure Boot BypassBlackLotus downgraded the Windows Boot Manager to signed but vulnerableversion of itUEFI FirmwareUEFI Boot ManagerWindows Boot ManagerWindows Boot Loader

5、Windows KernelVerifyVerifyVerifyVerifyRevocation ListMicrosofts Mitigation Against Secure Boot DowngradesMicrosofts mitigation included adding signed but vulnerable boot managers to revocation listsRevoked boot managers are not allowedUEFI FirmwareUEFI Boot ManagerWindows Boot ManagerWindows Boot Lo

6、aderWindows KernelVerifyVerifyVerifyVerifyResearch MotivationAre there any components affected by downgrade attacks other then Secure Boot?Research GoalsEvaluate the state of downgrade attacks on WindowsFind if any other critical components have been overlookedDowngrade VisionBring Your Own Vulnerab

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(阿隆·列维夫_利用Windows更新的降级攻击.pdf)为本站 (张5G) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠