Reverse Engineering a tcpip.sys DOS Vulnerability

Опубликовано: 22 Октябрь 2024
на канале: Off By One Security
1,986
119

This stream starts off with 20-30 minutes of talk around exploit sales and other related items. Then we get into reverse engineering, patchdiffing, and exploiting an older tcpip.sys DOS vulnerability. This one in particular is interesting as it can be used to tie up network resources on a server until the NIC is disabled and re-enabled.

If you'd like to play around with the tcpip.sys unpatched and patched driver files, as well as the Python script used to exploit the vulnerability, you can download the files here: https://1drv.ms/u/s!Aiumfng0i0zPiwEQy...

The Python script was written back before Python 3 and I never updated it, but it still works fine. The SHA-1 hashes of the tcpip.sys files are:

Unpatched: ca5e034d846c9e8945b2704b94f2d08777013c08
Patched: e3d46d9db4e0c29859c71bb39e7525ea55d39813