婆罗门
精华
|
战斗力 鹅
|
回帖 0
注册时间 2007-4-27
|
本帖最后由 Benighted 于 2024-7-22 23:21 编辑
你说推上那ZachVorhies的分析?早就被喷是不懂装懂了,具体debunking见 x.com/taviso/status/1814762302337654829
还是看CrowdStrike自己的事故分析吧,跟什么空指针没关系
https://www.crowdstrike.com/blog ... -technical-details/
Technical Details
On Windows systems, Channel Files reside in the following directory:
C:\Windows\System32\drivers\CrowdStrike\
and have a file name that starts with “C-”. Each channel file is assigned a number as a unique identifier. The impacted Channel File in this event is 291 and will have a filename that starts with “C-00000291-” and ends with a .sys extension. Although Channel Files end with the SYS extension, they are not kernel drivers.
Channel File 291 controls how Falcon evaluates named pipe1 execution on Windows systems. Named pipes are used for normal, interprocess or intersystem communication in Windows.
The update that occurred at 04:09 UTC was designed to target newly observed, malicious named pipes being used by common C2 frameworks in cyberattacks. The configuration update triggered a logic error that resulted in an operating system crash.
Channel File 291
CrowdStrike has corrected the logic error by updating the content in Channel File 291. No additional changes to Channel File 291 beyond the updated logic will be deployed. Falcon is still evaluating and protecting against the abuse of named pipes.
This is not related to null bytes contained within Channel File 291 or any other Channel File.
|
评分
-
查看全部评分
|