Re: Is GDT unsecure?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Jacky Luk (jl_at_knight.com)
Date: 04/24/04


Date: Sat, 24 Apr 2004 11:59:21 +0800

There are already heaps of blokes out there playing with kernel. I believe
it's way how Softice and IDA etc implement it. :)

"Alexander Grigoriev" <alegr@earthlink.net> ¼¶¼g©ó¶l¥ó·s»D
:#ztvpsaKEHA.2396@TK2MSFTNGP12.phx.gbl...
> Are you sure Ring3 can modify GDT? There is page protection mechanism...
>
> "Jacky Luk" <jl@knight.com> wrote in message
> news:Od3DxPaKEHA.1396@TK2MSFTNGP10.phx.gbl...
> > If you retrieve the base of the GDT, then counting upwards to find a
> > particular entry, modify the access rights, you could probably gain
access
> > of the whole address space + flags. How does Microsoft prevent this from
> > happening?
> > Thanks
> > Jack
> >
> >
>
>



Relevant Pages

  • Access rights changed on serial devices
    ... I use FC4 with kernel 2.6.11-1.1369_FC4. ... I noticed the access rights on /dev/ttyS1 were set to 660 and the device belongs ...
    (Fedora)
  • Re: chmod, chown and user, group
    ... > - delete this file even if I'm not member ... > So bash certainly doesn't handle access rights only via groups. ... Bash does not handle access rights. ... The kernel have a function called permission. ...
    (comp.os.linux.development.apps)