DEF CON 30 - Asaf Gilboa, Ron Ben-Yitzhak - Abusing Windows Error Reporting to Dump LSASS
This presentation will show a new method of dumping LSASS that bypasses current EDR defenses without using a vulnerability but by abusing a built-in mechanism in the Windows environment which is the WER (Windows Error Reporting) service.
WER is a built-in system in Windows designed to gather information about software crashes. One of its main features is producing a memory dump of crashing user-mode processes for further analysis.
We will present in detail and demo a new attack vector for dumping LSASS, which we dubbed LSASS Shtinkering, by manually reporting an exception to WER on the LSASS process without crashing it. The technique can also be used to dump the memory of any other process of interest on the system.
This attack can bypass defenses that wrongfully assume that a memory dump generated from the WER service is always a benign or non-attacker triggered activity.
The talk will take the audience through the steps and approach of how we reverse-engineered the WER dumping process, the challenges we found along the way, as well as how we have managed to solve them.
1 view
0
0
1 month ago 01:07:22 6
11-JAN-25 SSP Intentionally Start the California Wildfires, All Countries Temporarily Go to DEFCO...
4 months ago 00:00:00 1
Resonancerz - Let The Galaxy Burn
4 months ago 00:03:09 1
Jay Z - 99 Problems OFFICIAL VIDEO
4 months ago 00:00:00 1
Classic Rock Songs 70s 80s 90s Full Album - Queen, Eagles, Pink Floyd, Def Leppard, Bon Jovi
4 months ago 00:00:00 1
Top 100 Classic Rock Songs Of All Time - ACDC, Pink Floyd, Eagles, Queen, Def Leppard, Bon Jovi
4 months ago 00:01:29 1
Peaceful 31
4 months ago 00:04:54 1
Los Borbones son unos Ladrones VIDEOCLIP + LETRA
5 months ago 01:14:27 1
[Angels Of Love] Dave Morales ’’Revoluciòn’’ live @ Disco Metropolis 31-08-2002
5 months ago 00:03:19 9
NOELIA RODILES & FERNANDO ARIAS en FILARMÓNICA DE ZARAGOZA. Letanía D 343 de
5 months ago 00:46:42 1
ЛУЧШИЕ ИГРЫ про ХОЛОДНУЮ ВОЙНУ
5 months ago 00:35:15 1
The Absolute Craziest Mind Blowing Knives / Stuff at a Knife Show
5 months ago 01:04:33 2
Danny Eaton Guestmix
5 months ago 00:22:46 1
PREPARE YOUR FAMILY FOR A FULL SCALE EVACUATION OF THE URBAN AREAS BEFORE SHTF!
5 months ago 00:42:23 1
⚡ALERT: WW3 GROUND WAR BEGINS! US SENDS TROOPS! KREMLIN/ IRAN EMERGENCY! PUTIN GOES DEFCON 2!
5 months ago 00:02:22 1
Les manifestations après le décès de Philippine
5 months ago 00:44:06 1
DEF CON 25 - Chris Sumner - Rage Against the Weaponized AI Propaganda Machine
5 months ago 00:04:38 1
VIEUX CON !
5 months ago 00:00:00 1
Mamy Samb et Ngoné à Bougane “nagn ko barricadé nakh mou bagna guénati def conférence presse“
5 months ago 00:04:02 1
Resonancerz - Power Of Harmony
5 months ago 00:15:23 1
Russian short film – “Defcon“ (2009)
5 months ago 00:08:22 1
“Rusia entraría en DEFCON4 si Zelensky usa los misiles de largo alcance de EEUU”. Villaroya
5 months ago 01:33:23 1
Cyber Risk Thursday: Internet of Bodies
5 months ago 02:03:39 1
Ori Uplift - Uplifting Only 422 (March 11, 2021) [All Instrumental]