Heckenkamp, 27
United States v. Jeansonne, 26
United States v. Rocci, 38
United States v. Sklyarov, 38
United States v. Whitehead, 38
United States v. Williams, 27
unpacking binaries, 525??“533
debugger-assisted unpacking, 528??“529
IDA-assisted unpacking, 529??“533
run and dump unpacking, 527??“528
UPX, 511, 527
U.S. Department of Veteran??™s Affairs, 8
USA Patriot Act, 35??“36, 39
user responsibilities, 71
V
valgrind, 345??“348
validation, 58??“61
vendors, 47??“48
virtual tables. See vtables
viruses, 500
and the CFAA, 26
See also malware
VM detection, 501, 506??“507
VMware, setup, 508
vtables, 323??“325
vulnerabilities
after fixes are in place, 67
amount of time to develop fixes for,
46??“47
client-side vulnerabilities, 83??“91,
359??“361, 363??“369
documenting problems, 478??“479
in Mac OS X, 43??“44
in Microsoft products, 41
RRAS vulnerabilities, 76??“83
understanding, 466
vulnerability analysis. See passive analysis
vulnerability summary report (VSR), 56
W
Walleye web interface, 505??“506
white box testing, 335
wilderness, 180
WinDbg, 246
Windows Access Control, 388??“389
access control entries (ACEs), 394??“397
access tokens, 390??“393
AccessCheck function, 397??“400
attacking services, 418??“424
attacking weak DACLs in the Windows
registry, 424??“428
attacking weak directory DACLs, 428??“432
attacking weak file DACLs, 433??“436
Authenticated Users group, 406
authentication SIDs, 406??“408
Discretionary Access Control List
(DACL), 394
dumping the process token, 401??“403
dumping the security descriptor, 403??“406
Everyone group, 406
investigating ???access denied???, 409??“412
LOGON SIDs, 408
NULL DACL, 408??“409
precision desiredAccess requests, 413??“417
rights of ownership, 408
security descriptors (SDs), 394??“396
security identifiers (SIDs), 389??“390
special SIDs, 406
System Access Control List (SACL), 394
See also access control
Windows exploits
building a basic Windows exploit,
258??“265
building the exploit sandwich, 263??“265
common problems leading to exploitable
conditions, 285??“286
compiling on Windows, 243??“245
crashing meet.
Pages:
919
920
921
922
923
924
925
926
927
928
929
930
931
932