06.11.2015 Views

Practical SMEP bypass techniques on Linux

RUXCON15-Vitaly

RUXCON15-Vitaly

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<str<strong>on</strong>g>SMEP</str<strong>on</strong>g><br />

• Check if <str<strong>on</strong>g>SMEP</str<strong>on</strong>g> is enabled:<br />

• cat /proc/cpuinfo | grep smep # (no root required)<br />

• Disable <str<strong>on</strong>g>SMEP</str<strong>on</strong>g> (“nosmep” kernel parameter)<br />

• Hypervisors<br />

• Xen, VMWare - <str<strong>on</strong>g>SMEP</str<strong>on</strong>g> support<br />

• VirtualBox, Hyper-V - no <str<strong>on</strong>g>SMEP</str<strong>on</strong>g> support<br />

• VMWare - virtualHW.versi<strong>on</strong> “8” or below - no <str<strong>on</strong>g>SMEP</str<strong>on</strong>g> support

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!