6 ms·
Hiding execution of unsigned code in Windows system threads
- londons_explore 6y agoI thought the windows kernel was locked down to signed code only by Microsoft's patchguard? Wouldn't any opportunity to run your own code in the kernel be worthy of a bug bounty? Are the protections nowhere near as strong as intended?
- smileybarry 6y agoThat's two separate mechanisms; PatchGuard protects against hooking and rewriting sections of the kernel, and the kernel only loads signed drivers (and since 2016-ish only Microsoft-signed).
- mckirk 6y agoThere is so many ways of running your own code in the kernel (mainly thanks to signed, but terribly written drivers [1]) that PatchGuard really is only a nuisance if you need to overwrite some kernel functionality, e.g. for hooking functions. So a rootkit needs to worry about PatchGuard, but if you only want to run code at kernel level, you generally don't. [1]: https://www.unknowncheats.me/forum/anti-cheat-bypass/334557-vulnerable-driver-megathread.html https://www.unknowncheats.me/forum/anti-cheat-bypass/334557-...
- eznzt 6y agoCan I install those drivers and do they run even if I don't own the pertinent hardware?
- freeone3000 6y agoDrivers don't require any particular hardware to function -- they can be triggered to autoload on hardware detection, but you can also trigger them on demand, or on startup. As an example, ProcExp uses a driver to list open handles. If you're interested in running kernel code on your own device, it's simpler to just write your own driver.
- eznzt 6y agoYou can't run unsigned kernel drivers unless you boot the operating system in test mode, right?
- freeone3000 6y agoCorrect. It's advisable to do it on a VM or another computer you own, rather than your main computer.
- eznzt 6y agoSure, but this is in the context of wanting to run kernel code to cheat in a video game (which is what that forum post is about)
- deleted 6y ago[deleted]
- freeone3000 6y agoI feel like I'm missing something here. You can run games in test mode. Anticheat code will obviously trip, hence, the hiding... But anticheat also trips if you have the wrong brand of mouse. The context is informative, but doesn't really change anything?
- eznzt 6y agoFortnite for example refuses to run if you boot in test mode. I don't play online much so I assumed it was standard behaviour in multiplayer games.
- zinekeller 6y agoWell, in this case the user really wants to modify the system so they can either 1) run it with Secure boot disabled, 2) use poorly-coded or outdated kernel drivers such as the list mentioned by mckirk (https://news.ycombinator.com/item?id=25766871 https://news.ycombinator.com/item?id=25766871) to bypass NT policies, or 3) Install Windows in BIOS/CSM mode (so that the only hindrance is the generation of root certificates, unlike with UEFI installations which triggers the kernel to check if the drivers loaded is blessed by Microsoft).
- userbinator 6y ago"tamper". That connotation is intentional. MS wants to take control away from users and owners, so uses such language. How about "modify" or "customise"? No, because that wouldn't fit their authoritarian narrative.
- zinekeller 6y agoNoted and changed. > MS wants to take control away from users and owners, so uses such language. I wanted to clarify this issue in logner detail but obviously outside of enterprise settings (which the owner does not trust the user). Now, I'm writing to HN here, which really likes its freedoms (and I also want it). But the general pattern nowadays is that people value the consistency over customisability. The success of locked-down iPhone and Android is a great example: sure some users wants to run other software on the device but the simple truth is vast majority of users prefers to trust Apple or Google to do their job properly as their main goal is not to run a computer but rather to do their own business (similar to how a company often contracts its electricity, water, network connectivity, waste management and others). On a similar vein, the newer versions of Windows will run with the secure boot option enabled (which will ensure that the system is as intended by Microsoft). Again, some people wants the system to be easily modifiable, and in that case there are ways to lower the guardrails to allow you to a certain extent. But the vast majority of users trusts Microsoft to manage the system and let them just do work. TLDR: Some users view a computer as something to tinker upon but most users see it as a tool to be used.
- 6y ago
- lights0123 6y agoAPC means asynchronous procedure call, for anyone else unfamiliar with the term. https://docs.microsoft.com/en-us/windows-hardware/drivers/kernel/types-of-apcs https://docs.microsoft.com/en-us/windows-hardware/drivers/ke...