Explore the intricacies of Windows security mechanisms in this 27-minute conference talk from OffensiveCon23. Delve into the MojoBlob Registry, examining its code structure, service-side dispatch, and message validation processes. Gain insights into dispatch validators, request and response IDs, provider interfaces, and type confusion. Learn about potential security implications, including the classic blob registry and ways to disable message validation. Understand how these components interact and impact Windows system security through practical demonstrations and expert analysis.
What's in a Name? Exploring MojoBlob Registry and Service Side Dispatch