Главная
Study mode:
on
1
Intro
2
Story
3
Overview
4
What is Mojo
5
Blob Registry
6
Code Structure
7
Service Side Dispatch
8
Message Dispatch
9
Return Types
10
Dispatch
11
Validator
12
Request ID
13
Response ID
14
Provider Interface
15
Type Confusion
16
Demo
17
Quote
18
Handles
19
Lunch time
20
Disable message validation
21
Classic blob registry
Description:
Explore the intricacies of Windows security mechanisms in this 27-minute conference talk from OffensiveCon23. Delve into the MojoBlob Registry, examining its code structure, service-side dispatch, and message validation processes. Gain insights into dispatch validators, request and response IDs, provider interfaces, and type confusion. Learn about potential security implications, including the classic blob registry and ways to disable message validation. Understand how these components interact and impact Windows system security through practical demonstrations and expert analysis.

What's in a Name? Exploring MojoBlob Registry and Service Side Dispatch

OffensiveCon
Add to list
0:00 / 0:00