4 ms·
This doesn't "bypass all Windows security measures". As of Windows 8, processes can disable win32k syscalls using SetProcessMitigationPolicy with ProcessSystemC
by mdriley 12y ago
This doesn't "bypass all Windows security measures". As of Windows 8, processes can disable win32k syscalls using SetProcessMitigationPolicy with ProcessSystemCallDisablePolicy.
https://msdn.microsoft.com/en-us/library/windows/desktop/hh769088%28v=vs.85%29.aspx https://msdn.microsoft.com/en-us/library/windows/desktop/hh7...
- XbcL4QZQ 12y agoIs ProcessSystemCallDisablePolicy somehow similar to seccomp on Linux? I understand that seccomp allows to selectively allow/disallow individual system calls while this disallows all win32k calls. But I don't know how similar these features are in the security impact. Apparently, chromium - which uses seccomp on linux - uses ProcessSystemCallDisablePolicy on windows: https://src.chromium.org/chrome/branches/1312/src/sandbox/win/src/process_mitigations.cc https://src.chromium.org/chrome/branches/1312/src/sandbox/wi...
- mdriley 12y agoThey're comparable features. In both cases, a simple but hardened filter is placed in front of some part of the kernel attack surface. Vulnerable processes (e.g. renderers) opt in to these protections so that, in the event of compromise, they're less likely to be vectors for a successful escalation of privilege attack against the kernel syscall interface.