{"id":226,"date":"2022-05-22T17:10:41","date_gmt":"2022-05-22T15:10:41","guid":{"rendered":"https:\/\/areyou1or0.it\/?p=226"},"modified":"2022-08-13T17:45:39","modified_gmt":"2022-08-13T15:45:39","slug":"hevd-windows-kernel-exploitation-setup-the-environment","status":"publish","type":"post","link":"https:\/\/areyou1or0.it\/index.php\/2022\/05\/22\/hevd-windows-kernel-exploitation-setup-the-environment\/","title":{"rendered":"HEVD Windows Kernel Exploitation 1 \u2013 Setup the Environment"},"content":{"rendered":"\n<p>There will be few setup steps we need to follow before we jump into the Kernel Exploitation:<\/p>\n\n\n\n<p>Install Windows x86 in VM<\/p>\n\n\n\n<ol><li>Install WinDBG<\/li><\/ol>\n\n\n\n<p>2. Setup the Debugging Symbols<\/p>\n\n\n\n<ul><li>computer &#8211; properties &#8211; advanced system settings &#8211; emvironmental variables<\/li><li>create a sys variable<\/li><li>Variable Name:&nbsp;<strong>_NT_SYMBOL_PATH<\/strong><\/li><li>Variable Value:&nbsp;<em>SRV*C:\\Symbols*https:\/\/msdl.microsoft.com\/download\/symbols<\/em><\/li><\/ul>\n\n\n\n<p>3. Enable Debugging in BCD<\/p>\n\n\n\n<p>Run CMD as administrator and type the followings<\/p>\n\n\n\n<ul><li>bcdedit&nbsp;\/<strong>copy<\/strong>&nbsp;{current} \/d &#8220;Win7Dbg&#8221;<\/li><li>bcdedit&nbsp;\/debug {&#8230;&#8230;&#8230;&#8230;} on&nbsp;<\/li><li>bcdedit&nbsp;\/dbgsettings<\/li><\/ul>\n\n\n\n<p>4. Create the Debugee VM<\/p>\n\n\n\n<ul><li>power of the debugger VM<\/li><li>create a linked clone<\/li><\/ul>\n\n\n\n<p>5. Enable Serial Ports on Vmware <\/p>\n\n\n\n<ul><li>go to Library, right click, press Option, edit the config file<\/li><\/ul>\n\n\n\n<p>Add Device &#8211; Serial Port<\/p>\n\n\n\n<p>** note that I use VMware Fusion on my mac and you can edit the config file by clicking the Option key with right click in VMware library<\/p>\n\n\n\n<ul><li>serial0.present = &#8220;TRUE&#8221;<\/li><li>serial0.fileType = &#8220;pipe&#8221;<\/li><li>serial0.fileName = &#8220;\/tmp\/serial&#8221;<\/li><li>serial0.pipe.endPoint = &#8220;server&#8221;<\/li><\/ul>\n\n\n\n<p><\/p>\n\n\n\n<ul><li>serial0.present = &#8220;TRUE&#8221;<\/li><li>serial0.fileType = &#8220;pipe&#8221;<\/li><li>serial0.fileName = &#8220;\/tmp\/serial&#8221;<\/li><li>serial0.pipe.endPoint = &#8220;client&#8221;<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"400\" height=\"251\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/debugger-vmx.png\" alt=\"\" class=\"wp-image-227\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/debugger-vmx.png 400w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/debugger-vmx-300x188.png 300w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/figure>\n\n\n\n<p>6. Start the Debugger Machine<\/p>\n\n\n\n<p>Debugger machine &#8211; start normally (without the debugger mode)<br>Go to WinDBG &#8211; File &#8211; kernel debug &#8211; COM<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"619\" height=\"449\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-20-at-16.25.41.png\" alt=\"\" class=\"wp-image-228\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-20-at-16.25.41.png 619w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-20-at-16.25.41-300x218.png 300w\" sizes=\"(max-width: 619px) 100vw, 619px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"708\" height=\"400\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-20-at-16.26.13.png\" alt=\"\" class=\"wp-image-229\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-20-at-16.26.13.png 708w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-20-at-16.26.13-300x169.png 300w\" sizes=\"(max-width: 708px) 100vw, 708px\" \/><\/figure>\n\n\n\n<p>7. Start the Debuggee Machine<\/p>\n\n\n\n<p>Choose Win7DBG &#8211; debugger enabled<br>Check the debugger machine again for such screen<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"602\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.02.15-1024x602.png\" alt=\"\" class=\"wp-image-230\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.02.15-1024x602.png 1024w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.02.15-300x176.png 300w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.02.15-768x452.png 768w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.02.15.png 1505w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Hit Break button to get an interactive &gt;kd prompt<\/p>\n\n\n\n<p>let&#8217;s check if the symbols were loaded correctly:<\/p>\n\n\n\n<p>!sym noisy<br>.reload<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"536\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.04.27-1024x536.png\" alt=\"\" class=\"wp-image-231\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.04.27-1024x536.png 1024w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.04.27-300x157.png 300w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.04.27-768x402.png 768w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.04.27.png 1455w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>8. Download HEDV and OSR Driver Loader<\/p>\n\n\n\n<p>Load the driver on debugee VM<br>\u2022 choose the driver path<br>\u2022 set Service start: Automatic<br>\u2022 Register Service<br>\u2022 Start Service<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"672\" height=\"892\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.09.43.png\" alt=\"\" class=\"wp-image-232\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.09.43.png 672w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.09.43-226x300.png 226w\" sizes=\"(max-width: 672px) 100vw, 672px\" \/><\/figure>\n\n\n\n<p>Check on the debugger machine to see if the driver is loaded<\/p>\n\n\n\n<p>lm m H*<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"745\" height=\"257\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.40.07.png\" alt=\"\" class=\"wp-image-233\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.40.07.png 745w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2021-12-28-at-16.40.07-300x103.png 300w\" sizes=\"(max-width: 745px) 100vw, 745px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"540\" src=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2022-04-14-at-17.44.46-1024x540.png\" alt=\"\" class=\"wp-image-234\" srcset=\"https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2022-04-14-at-17.44.46-1024x540.png 1024w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2022-04-14-at-17.44.46-300x158.png 300w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2022-04-14-at-17.44.46-768x405.png 768w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2022-04-14-at-17.44.46-1536x810.png 1536w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2022-04-14-at-17.44.46-2048x1080.png 2048w, https:\/\/areyou1or0.it\/wp-content\/uploads\/2022\/05\/Screenshot-2022-04-14-at-17.44.46-1568x827.png 1568w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>There will be few setup steps we need to follow before we jump into the Kernel Exploitation: Install Windows x86 in VM Install WinDBG 2. Setup the Debugging Symbols computer &#8211; properties &#8211; advanced system settings &#8211; emvironmental variables create a sys variable Variable Name:&nbsp;_NT_SYMBOL_PATH Variable Value:&nbsp;SRV*C:\\Symbols*https:\/\/msdl.microsoft.com\/download\/symbols 3. Enable Debugging in BCD Run CMD as&hellip; <a class=\"more-link\" href=\"https:\/\/areyou1or0.it\/index.php\/2022\/05\/22\/hevd-windows-kernel-exploitation-setup-the-environment\/\">Continue reading <span class=\"screen-reader-text\">HEVD Windows Kernel Exploitation 1 \u2013 Setup the Environment<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[21],"tags":[],"_links":{"self":[{"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/posts\/226"}],"collection":[{"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/comments?post=226"}],"version-history":[{"count":4,"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/posts\/226\/revisions"}],"predecessor-version":[{"id":255,"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/posts\/226\/revisions\/255"}],"wp:attachment":[{"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/media?parent=226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/categories?post=226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/areyou1or0.it\/index.php\/wp-json\/wp\/v2\/tags?post=226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}