flat assembler
Message board for the users of flat assembler.
  
       
      Index
      > Windows > About FS register in Windows OS | 
  
| Author | 
  | 
              
| 
                  
                   typedef 13 Aug 2011, 02:38 
                  Reference:
 
                  
                http://en.wikipedia.org/wiki/Win32_Thread_Information_Block Code: FS:[0x124] Pointer to KTHREAD (ETHREAD) structure which is the biggest structure I've ever seen: http://www.nirsoft.net/kernel_struct/vista/KTHREAD.html Look at this field: PVOID KernelStack; What does make you think ? Maybe with some tweaks we may end up injecting some code into ring0. What do you think ?  | 
              |||
                  
  | 
              
| 
                  
                   vid 13 Aug 2011, 08:33 
                  It's not going to be so easy, hundreds of researchers keep inspecting Windows code for vulnerabilities. 
                  
                 | 
              |||
                  
  | 
              
| 
                  
                   addes3 13 Aug 2011, 18:51 
                  They may be reading this topic... 
                  
                 | 
              |||
                  
  | 
              
< Last Thread | Next Thread >  | 
    
Forum Rules: 
  | 
    
Copyright © 1999-2025, Tomasz Grysztar. Also on GitHub, YouTube.
Website powered by rwasa.