[HN Gopher] LOLDrivers - Living Off the Land Drivers
___________________________________________________________________
LOLDrivers - Living Off the Land Drivers
Author : sacrosanct
Score : 43 points
Date : 2023-04-07 19:57 UTC (3 hours ago)
(HTM) web link (www.loldrivers.io)
(TXT) w3m dump (www.loldrivers.io)
| SCHiM wrote:
| This is a webpage collecting a list of (signed?) drivers that may
| be loaded into the Windows kernel and thereby escalate
| privileges. Because the Windows kernel doesn't support loading
| drivers that are not signed by Microsoft, attackers have to
| resort to exploiting legitimate signed drivers to gain access to
| the kernel once they've obtained Administrator (root) or SYSTEM
| (root) privileges.
|
| A central list of exploitable drivers serves as a starting point
| for both attackers and defenders. Attackers can use it for their
| research if they want to raise their privileges by loading code
| into the kernel (rootkits), or attack protected processes (PPL
| and up, think anti-virus and anti-malware processes, DRM). For
| defenders it serves as a curated list of drivers to look out for
| in their environment. For example, to raise alerts if a Lenovo
| driver is loaded on a Dell system.
|
| A similar site is the LolBAS site, where signed Windows binaries
| are listed for their ability to serve as trusted "proxy"
| executables into which attackers can somehow inject or load their
| code.
| [deleted]
| [deleted]
| 0x69420 wrote:
| i'm not really a security guy but... is ibm poland ok? that's one
| hell of an outlier
| thriftwy wrote:
| Maybe they have published a lot of different revisions of the
| same vulnerable driver?
| vuln wrote:
| Nice! LolBAS and gtfobins are great projects. I've used both
| extensively. I can't wait until Monday to start running this
| against my environment. Down the rabbit hole I go at 4pm on a
| Friday! Appreciate the hard work.
| colinsane wrote:
| what does the name mean ("Living Off the Land")? i expected some
| homesteading tools or something -- does the phrase have some
| history in the security world?
| jabroni_salad wrote:
| LOTL means that the adversary is using tools already present on
| that computer instead of trying to download even more malware.
| This strategy is popular because not writing any files makes
| you immune to filescanners.
| teeray wrote:
| I honestly thought this was going to be a forum for big rig
| truckers that also hunted and trapped their own food or
| something.
| tmtvl wrote:
| I was also expecting something like survivalists who live in
| their pickup truck or something.
| ghostpepper wrote:
| It means essentially that. The alternative is an attacker
| bringing/installing their own tools post-compromise.
|
| Living off the land is more stealthy because you're using
| legitimate system tools to do malicious activities
| [deleted]
| ronsor wrote:
| Ah yes, the venerable MHYProt is included in the list. I do love
| gaming anticheats; they make loading cheats so easy.
___________________________________________________________________
(page generated 2023-04-07 23:01 UTC)