WinKern x64 - Use After Free

120 Points  0x0

Reversez le driver, trouvez les vulnerabilités qu’il expose et exploitez les sur un système Windows 10, afin d’obtenir les privilèges SYSTEM

Author

__syscallSynacktiv,  

Level  Difficulty

Validations

5 Challengers 1%

Note  Notation

14 Votes

To reach this part of the site please login

  Solution

Challenge Results Challenge Results

Pseudo Challenge Lang date
hyliad   WinKern x64 - Use After Free 11 May 2020 at 09:55
kikko   WinKern x64 - Use After Free 21 April 2020 at 17:54
Tomtombinary   WinKern x64 - Use After Free 3 April 2020 at 18:20
BenK   WinKern x64 - Use After Free 28 March 2020 at 19:19
macz   WinKern x64 - Use After Free 5 February 2020 at 14:01

 75 Challenges

Results Name Validations Number of points  Explanation for the scores Difficulty  Difficulty Author Note  Notation Solution
pas_valide ELF x86 - Stack buffer overflow basic 1 8% 14081 5 Lyes 11
pas_valide ELF x86 - Stack buffer overflow basic 2 6% 10130 10 Lyes 10
pas_valide PE32 - Stack buffer overflow basic 1% 453 10 Ech0 5
pas_valide ELF x86 - Format string bug basic 1 4% 6616 15 Lu33Y 5
pas_valide ELF x64 - Stack buffer overflow - basic 3% 4993 20 Arod 6
pas_valide ELF x86 - Format string bug basic 2 2% 3275 20 Lyes 5
pas_valide ELF x86 - Race condition 3% 4507 20 Lu33Y 9
pas_valide ELF ARM - Stack buffer overflow - basic 1% 898 25 pickle 7
pas_valide ELF MIPS - Stack buffer overflow - No NX 1% 273 25 franb 2
pas_valide ELF x86 - Stack buffer overflow basic 3 2% 3301 25 Lyes 3
pas_valide ELF x86 - Use After Free - basic 1% 777 25 Esad 3
pas_valide PE32 - Advanced stack buffer overflow 1% 84 25 Ech0 3
pas_valide ELF ARM - Stack Spraying 1% 159 30 pickle 4
pas_valide ELF x86 - BSS buffer overflow 2% 3240 30 Lu33Y 7
pas_valide ELF x86 - Stack buffer overflow basic 4 2% 2150 30 Lu33Y 5
pas_valide ELF x86 - Stack buffer overflow basic 6 2% 1933 30 TiWim 5
pas_valide ELF x86 - Format String Bug Basic 3 1% 874 35 Lyes 2
pas_valide ELF ARM - Basic ROP 1% 447 40 pickle 5
pas_valide ELF MIPS - Basic ROP 1% 82 40 dagger 1
pas_valide ELF x86 - Stack buffer overflow - C++ vtables 1% 617 40 sebbb 2
pas_valide PE32+ Format string bug 1% 38 40 Ech0 1
pas_valide ELF x64 - Logic bug 1% 131 50 sbrk 3
pas_valide ELF x86 - Bug Hunting - Several issues 1% 68 50 sbrk 1
pas_valide ELF x86 - Stack buffer and integer overflow 1% 1549 50 Lu33Y 3
pas_valide ELF x86 - Stack buffer overflow - ret2dl_resolve 1% 124 50 kikko 0
pas_valide ELF x86 - Stack buffer overflow basic 5 1% 1422 50 Lu33Y 1
pas_valide ELF x64 - Stack buffer overflow - advanced 1% 906 55 Arod 4
pas_valide ELF MIPS - Format String Glitch 1% 37 60 pickle, martin 1
pas_valide ELF x86 - Information leakage with Stack Smashing Protector 1% 654 60 Arod 2
pas_valide ELF ARM - Race condition 1% 93 70 pickle 1
pas_valide ELF x64 - Browser exploit - Intro 1% 53 70 pickle 1
pas_valide ELF x86 - Out of bounds attack - French Paradox 1% 78 70 sbrk 3
pas_valide ELF x86 - Remote BSS buffer overflow 1% 658 75 Tosh 1
pas_valide ELF x86 - Remote Format String bug 1% 816 75 Tosh 2
pas_valide PE32+ Basic ROP 1% 16 75 Ech0 0
pas_valide ELF x64 - Remote heap buffer overflow - fastbin 1% 204 80 franb 1
pas_valide ELF x86 - Blind remote format string bug 1% 231 80 Lyes 1
pas_valide LinKern ARM - vulnerable syscall 1% 91 85 pickle 0
pas_valide LinKern x86 - Buffer overflow basic 1 1% 331 85 franb 2
pas_valide LinKern x86 - Null pointer dereference 1% 339 90 franb 0
pas_valide LinKern x64 - Race condition 1% 209 95 franb 0
pas_valide ELF ARM - Alphanumeric shellcode 1% 29 100 pickle 2
pas_valide ELF MIPS - URLEncoded Format String bug 1% 17 100 pickle 0
pas_valide ELF x86 - Hardened binary 1 1% 572 100 sm0k 3
pas_valide ELF x86 - Hardened binary 2 1% 455 100 sm0k 3
pas_valide ELF x86 - Hardened binary 3 1% 286 100 sm0k 1
pas_valide ELF x86 - Hardened binary 4 1% 318 100 sm0k 2
pas_valide LinKern MIPSel - Vulnerable ioctl 1% 29 100 pickle 0
pas_valide LinKern x64 - reentrant code 1% 110 100 franb 1
pas_valide ELF ARM - Heap format string bug 1% 54 105 franb 0
pas_valide ELF x64 - Sigreturn Oriented Programming 1% 189 105 Arod 3
pas_valide ELF ARM - Format String bug 1% 65 110 pickle 1
pas_valide ELF ARM - Use After Free 1% 61 110 pickle 0
pas_valide ELF x64 - Heap feng-shui 1% 50 110 laxa 2
pas_valide ELF x64 - Off-by-one bug 1% 95 110 NeedToLearn 2
pas_valide ELF x86 - Hardened binary 5 1% 245 110 sm0k 1
pas_valide LinKern ARM - Stack Overflow 1% 37 110 pickle 0
pas_valide LinKern x86 - basic ROP 1% 164 110 franb 1
pas_valide ELF ARM - Heap Off-by-One 1% 35 115 pickle 1
pas_valide ELF x64 - Remote Heap buffer overflow 1 1% 124 115 Tosh 3
pas_valide ELF x86 - Hardened binary 6 1% 228 115 sm0k 3
pas_valide ELF x86 - Hardened binary 7 1% 191 115 Tosh 3
pas_valide ELF x86 - Remote stack buffer overflow - Hardened 1% 113 115 franb 1
pas_valide LinKern x64 - RowHammer 1% 40 115 pickle 1
pas_valide LinKern x64 - SLUB off-by-one 1% 23 115 Tosh 1
pas_valide ELF ARM - Heap buffer overflow - Wilderness 1% 23 120 pickle 1
pas_valide ELF ARM - Heap Overflow 1% 25 120 pickle 1
pas_valide ELF x64 - Seccomp Whitelist 1% 38 120 pickle 0
pas_valide ELF x86 - Blind ROP 1% 90 120 franb 0
pas_valide Linkern x64 - Memory exploration 1% 74 120 franb 1
pas_valide WinKern x64 - Advanced stack buffer overflow - ROP 1% 6 120 __syscall, Synacktiv 0
pas_valide WinKern x64 - Use After Free 1% 5 120 __syscall, Synacktiv 0
pas_valide ELF x64 - Remote Heap buffer overflow 2 1% 89 130 Tosh, Fritz 1
pas_valide ELF x64 - Blind ROP 1% 58 135 franb 1
pas_valide ELF x64 - Browser exploit - BitString 1% 19 135 pickle 0