DEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant Drive @HackersOnBoard
DEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant Drive  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 2 days ago
For software to communicate with hardware, it needs to talk to a kernel-mode driver that serves as a middle-man between the two, helping to make sure everything operates as it should. In Windows that is done using the Kernel-Mode Driver Framework (KMDF).

These drivers are used to control everything in your computer, from small things like CPU fan speed, color of your motherboard LED lights, up to flashing a new BIOS.

However, as the code in these drivers runs with the same privileges as the rest of the kernel, malicious drivers can be used to compromise the security of the platform. To that end, Microsoft relies on WHQL, code signing, and EV Signing to prevent drivers which have not been approved by Microsoft from being loaded into the kernel.

Unfortunately, security vulnerabilities in signed drivers can be used to as a proxy to read and write hardware resources such as kernel memory, internal CPU configuration registers, PCI devices, and more. These helpful driver capabilities can even be misused to bypass and disable Windows protection mechanisms.

Let us teach you how these drivers work, show you the unbelievable risk they pose, and enjoy our walk of shame as we parade all the silly and irresponsible things we discovered in our research.
DEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant DriveDEF CON 27 - Joe Grand Kingpin - Behind the Scenes of the DEFCON 27 BadgeBlack Hat USA 2018 - A Brief History of Mitigation The Path to EL1 in iOS 11Black Hat USA 2018 - Reconstruct the World from Vanished Shadow Recovering Deleted VSS SnapshotsDEF CON 27 - Intro to Embedded Hacking-How you can find a decade old bug in widely deployed devicesBlack Hat USA 2018 - WireGuard Next Generation Secure Network TunnelBlack Hat USA 2018 - A Dive in to Hyper V Architecture & VulnerabilitiesBlack Hat USA 2018 - Its a PHP Unserialization Vulnerability Jim, but Not as We Know ItBlack Hat USA 2018 - Measuring the Speed of the Red Queens Race - Adaption and Evasion in MalwareDEF CON 27 - Mike Spicer - I Know What You Did Last Summer 3 Years of Wireless Monitoring at DEF CONBlack Hat USA 2018 - Compression Oracle Attacks on VPN NetworksBlack Hat USA 2018 - Are You Trading Stocks Securely Exposing Security Flaws in Trading Technologies
HackersOnBoard |

DEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant Drive

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER