• XSS.stack #1 – первый литературный журнал от юзеров форума

Мануал/Книга Подборка материалов по исследованию уязвимостей в гипервизоре

weaver

31 c0 bb ea 1b e6 77 66 b8 88 13 50 ff d3
Забанен
Регистрация
19.12.2018
Сообщения
3 301
Решения
11
Реакции
4 622
Депозит
0.0001
Пожалуйста, обратите внимание, что пользователь заблокирован
Virtualization security Generalized deep technical
https://www.cs.ucr.edu/~heng/pubs/VDF_raid17.pdf
https://www.ernw.de/download/xenpwn.pdf
https://www.blackhat.com/docs/eu-16...tual-Device-Fuzzing-Framework-With-AFL-wp.pdf
https://www.syssec.ruhr-uni-bochum....entlichungen/2020/02/07/Hyper-Cube-NDSS20.pdf
https://www.troopers.de/downloads/t...ing_hypervisor_through_hardwear_emulation.pdf


Quality reference - system internals & vulndev primitives
https://www.exploit-db.com/docs/eng...-on-vulnerabilities-of-hypercall-handlers.pdf
https://census-labs.com/media/straightouttavmware-wp.pdf
https://www.blackhat.com/docs/eu-17...tudy-Of-Vmware-G2H-Escape-Vulnerabilities.pdf


Frontiers: Hyper-V, ESXi, speculative execution
https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/index.html
https://www.usenix.org/system/files/woot19-paper_zhao.pdf
https://blogs.technet.microsoft.com...anted-to-know-about-sr-iov-in-hyper-v-part-1/
https://www.blackhat.com/presentati...tation/BH07_Baker_WSV_Hypervisor_Security.pdf (2007!)
https://github.com/Microsoft/MSRC-Security-Research/blob/master/presentations/2019_02_OffensiveCon/2019_02 - OffensiveCon - Growing Hypervisor 0day with Hyperseed.pdf
https://blogs.technet.microsoft.com/srd/2019/01/28/fuzzing-para-virtualized-devices-in-hyper-v/
https://docs.microsoft.com/en-us/archive/blogs/jhoward/hyper-v-generation-2-virtual-machines-part-1
https://i.blackhat.com/us-18/Thu-Au...per-V-Through-Offensive-Security-Research.pdf


References
● Intel® 64 and IA-32 Architectures Software Developer’s Manual Combined Volumes: 1, 2A, 2B, 2C, 2D, 3A, 3B, 3C, 3D and 4
● TLFS: Microsoft Hypervisor Top Level Functional Specification
● Hyper-V Architecture
● Enhanced Session Mode
● Overview of Remote NDIS
● [MS-RNDIS]
● SLP: Service Location Protocol specification

Taken from


[GreHack 2024] Attacking hypervisors - A practical case
 
Последнее редактирование:


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх