Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
🌓
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
The Windows Registry Adventure #7: Attack surface analysis
projectzero.google
| 博客 |
#attack-surface
|
#fuzzing
|
#windows
|
#kernel
|
#research
|
#registry
摘要
Windows 注册表历险记第七篇:梳理哪些 Windows 组件会解析注册表数据,划定攻击面并圈定值得深入 fuzzing 与审计的高价值目标。
发布时间
2025-05-23 00:00
收录时间
2026-09-22 23:13
原文 ↗
← 上一篇
Policy and Disclosure: 2025 Edition
下一篇 →
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages
相关内容
博客
·
projectzero.google
The Windows Registry Adventure #6: Kernel-mode objects
Windows 注册表历险记第六篇:考察内核态注册表对象及其暴露的额外攻击面,并结合实例讨论其对权限提升研究的意义。
博客
·
projectzero.google
The Windows Registry Adventure #1: Introduction and research results
Windows 注册表历险记第一篇:介绍研究目标、方法,以及审计 Windows 注册表数据解析所得到的核心漏洞成果。
博客
·
projectzero.google
Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages
macOS 音频攻击面系列第一篇:通过发送 Mach message 对 CoreAudio 进行模糊测试,介绍攻击面构成、harness 设计与初期成果。
博客
·
projectzero.google
Driving forward in Android drivers
综述 Android 内核驱动攻击面:总结研究进展、反复出现的漏洞类型,以及驱动加固与后续安全工作的方向。
博客
·
projectzero.google
The Windows Registry Adventure #2: A brief history of the feature
Windows 注册表历险记第二篇:回顾注册表作为 Windows 特性的发展简史,以及其演变如何塑造了今天的攻击面。
博客
·
projectzero.google
Windows 内核字体模糊测试一周年(二):技术
Windows 内核字体引擎为期一年模糊测试系列第二篇:详解让该项目高效运转的具体技术与设计决策。
返回