Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
HackSysExtremeVulnerableDriver — HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux | Kitploit
도구/GitHubGitHub/hacksysteam/hacksysextremevulnerabledriver
Vulnerability AnalysisLearning & EducationBinary ExploitationLabs & Practice
GitHubhacksysteam/hacksysextremevulnerabledriver

HackSysExtremeVulnerableDriver

HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트
3.1k5841년 전Kitploit 검토 완료

HackSys Extreme Vulnerable Driver

root@kitploit:~
           ooooo   ooooo oooooooooooo oooooo     oooo oooooooooo.   
           `888'   `888' `888'     `8  `888.     .8'  `888'   `Y8b  
            888     888   888           `888.   .8'    888      888 
            888ooooo888   888oooo8       `888. .8'     888      888 
            888     888   888    "        `888.8'      888      888 
            888     888   888       o      `888'       888     d88' 
           o888o   o888o o888ooooood8       `8'       o888bood8P'   

Black Hat Arsenal Appveyor Build Status GitHub all Releases Twitter Follow Mastodon Follow Discord Server

HackSys Extreme Vulnerable Driver (HEVD) 는 의도적으로 취약하게 만든 Windows 커널 드라이버입니다. 보안 연구원과 애호가가 커널 수준 익스플로잇 기술을 향상시키기 위해 개발되었습니다.

HEVD는 단순한 스택 버퍼 오버플로우부터 사용 후 해제(use-after-free), 풀 버퍼 오버플로우, 경쟁 조건(race condition) 같은 더 복잡한 문제에 이르기까지 다양한 취약점을 제공합니다. 이를 통해 연구자들은 구현된 각 취약점에 대한 익스플로잇 기법을 탐구할 수 있습니다.

Black Hat Arsenal 2016

  • 프레젠테이션
  • 백서

블로그 포스트

  • http://www.payatu.com/hacksys-extreme-vulnerable-driver/

외부 익스플로잇

  • https://github.com/wetw0rk/Exploit-Development/tree/master/HEVD-Exploits
  • https://github.com/sam-b/HackSysDriverExploits
  • https://github.com/sizzop/HEVD-Exploits
  • https://github.com/badd1e/bug-free-adventure
  • https://github.com/FuzzySecurity/HackSysTeam-PSKernelPwn
  • https://github.com/theevilbit/exploits/tree/master/HEVD
  • https://github.com/GradiusX/HEVD-Python-Solutions
  • http://pastebin.com/ALKdpDsF
  • https://github.com/Cn33liz/HSEVD-StackOverflow
  • https://github.com/Cn33liz/HSEVD-StackOverflowX64
  • https://github.com/Cn33liz/HSEVD-StackCookieBypass
  • https://github.com/Cn33liz/HSEVD-ArbitraryOverwrite
  • https://github.com/Cn33liz/HSEVD-ArbitraryOverwriteGDI
  • https://github.com/Cn33liz/HSEVD-StackOverflowGDI
  • https://github.com/Cn33liz/HSEVD-ArbitraryOverwriteLowIL
  • https://github.com/mgeeky/HEVD_Kernel_Exploit
  • https://github.com/tekwizz123/HEVD-Exploit-Solutions
  • https://github.com/FULLSHADE/Windows-Kernel-Exploitation-HEVD

외부 블로그 게시물

  • https://wetw0rk.github.io/posts/0x00-introduction-to-windows-kernel-exploitation/
  • https://wetw0rk.github.io/posts/0x00-introducci%C3%B3n-a-windows-kernel-explotaci%C3%B3n/
  • https://wetw0rk.github.io/posts/0x01-killing-windows-kernel-mitigations/
  • https://wetw0rk.github.io/posts/0x01-mat%C3%A1ndo-windows-kernel-mitigaciones/
  • https://wetw0rk.github.io/posts/0x02-introduction-to-windows-kernel-uafs/
  • https://wetw0rk.github.io/posts/0x02-introducci%C3%B3n-a-windows-kernel-uafs/
  • https://wetw0rk.github.io/posts/0x03-approaching-the-modern-windows-kernel-heap/
  • https://wetw0rk.github.io/posts/0x03-acerc%C3%A1ndose-al-heap-moderno-del-windows-kernel/
  • https://wetw0rk.github.io/posts/0x04-writing-what-where-in-the-kernel/
  • https://wetw0rk.github.io/posts/0x04-escribiendo-que-donde-en-el-kernel/
  • https://wetw0rk.github.io/posts/0x05-introduction-to-windows-kernel-type-confusion-vulnerabilities/
  • https://wetw0rk.github.io/posts/0x05-introducci%C3%B3n-a-windows-kernel-type-confusion-vulnerabilidades/
  • https://wetw0rk.github.io/posts/0x06-approaching-modern-windows-kernel-type-confusions/
  • https://wetw0rk.github.io/posts/0x06-acerc%C3%A1ndose-a-windows-kernel-type-confusions-modernos/

저자

Ashfaq Ansari

ashfaq[at]hacksys[dot]io

블로그 | @HackSysTeam

HackSys Inc

https://hacksys.io/

스크린샷

드라이버 배너

도움말

익스플로잇

드라이버 디버그 출력

구현된 취약점

  • NULL 쓰기
  • Double Fetch
  • 버퍼 오버플로우
    • 스택
    • 스택 GS
    • NonPagedPool
    • NonPagedPoolNx
    • PagedPoolSession
  • 사용 후 해제
    • NonPagedPool
    • NonPagedPoolNx
  • 타입 혼동
  • 정수 오버플로우
    • 산술 오버플로우
  • 메모리 정보 노출
    • NonPagedPool
    • NonPagedPoolNx
  • 임의 증가
  • 임의 덮어쓰기
  • NULL 포인터 역참조
  • 초기화되지 않은 메모리
    • 스택
    • NonPagedPool
  • 안전하지 않은 커널 리소스 접근

드라이버 빌드

  1. Visual Studio 2017 설치
  2. Windows 드라이버 키트 설치
  3. 적절한 드라이버 빌더 Build_HEVD_Vulnerable_x86.bat 또는 Build_HEVD_Vulnerable_x64.bat 실행

다운로드

HackSys Extreme Vulnerable Driver를 소스에서 빌드하고 싶지 않다면 최신 릴리스의 사전 빌드된 실행 파일을 다운로드할 수 있습니다:

https://github.com/hacksysteam/HackSysExtremeVulnerableDriver/releases

드라이버 설치

OSR 드라이버 로더를 사용하여 HackSys Extreme Vulnerable Driver를 설치하십시오

테스트

HackSys Extreme Vulnerable Driver 및 해당 익스플로잇은 Windows 7 SP1 x86 및 Windows 10 x64에서 테스트되었습니다.

진행된 세션

  • Windows 커널 익스플로잇 1
  • Windows 커널 익스플로잇 2
  • Windows 커널 익스플로잇 3
  • Windows 커널 익스플로잇 4
  • Windows 커널 익스플로잇 5
  • Windows 커널 익스플로잇 6
  • Windows 커널 익스플로잇 7

진행된 워크숍

  • Windows 커널 익스플로잇 Humla Pune
  • Windows 커널 익스플로잇 Humla Mumbai

Linux용 HEVD

Linux HEVD 드라이버 배너

Linux HEVD 드라이버 설치 프로그램

Linux HEVD 드라이버 IOTCL 테스트

Linux HEVD 드라이버 IOTCL 로그

라이선스

복사 권한은 LICENSE 파일을 참조하십시오.

기여 지침

기여 지침은 CONTRIBUTING.md 파일을 참조하십시오.

TODO 및 버그 보고

개선 요청이나 버그 보고는 아래 주소의 GitHub 이슈 트래커를 통해 등록해 주십시오: https://github.com/hacksysteam/HackSysExtremeVulnerableDriver/issues

감사의 말

이 멋진 분들께 감사드립니다: 🎉


HackSys Inc

도구 다운로드
  • https://github.com/w4fz5uck5/3XPL01t5/tree/master/OSEE_Training
  • https://wetw0rk.github.io/posts/0x07-introduction-to-windows-kernel-race-conditions/
  • https://wetw0rk.github.io/posts/0x07-introducci%C3%B3n-a-windows-kernel-race-conditions/
  • https://wetw0rk.github.io/posts/0x08-modern-windows-kernel-race-conditions/
  • https://wetw0rk.github.io/posts/0x08-race-conditions-moderno-del-windows-kernel/
  • https://wetw0rk.github.io/posts/0x09-return-of-the-stack-overflow/
  • https://wetw0rk.github.io/posts/0x09-el-regreso-del-stack-overflow/
  • http://niiconsulting.com/checkmate/2016/01/windows-kernel-exploitation/
  • http://samdb.xyz/2016/01/16/intro_to_kernel_exploitation_part_0.html
  • http://samdb.xyz/2016/01/17/intro_to_kernel_exploitation_part_1.html
  • http://samdb.xyz/2016/01/18/intro_to_kernel_exploitation_part_2.html
  • http://samdb.xyz/2017/06/22/intro_to_kernel_exploitation_part_3.html
  • https://sizzop.github.io/2016/07/05/kernel-hacking-with-hevd-part-1.html
  • https://sizzop.github.io/2016/07/06/kernel-hacking-with-hevd-part-2.html
  • https://sizzop.github.io/2016/07/07/kernel-hacking-with-hevd-part-3.html
  • https://sizzop.github.io/2016/07/08/kernel-hacking-with-hevd-part-4.html
  • https://www.fuzzysecurity.com/tutorials/expDev/14.html
  • https://www.fuzzysecurity.com/tutorials/expDev/15.html
  • https://www.fuzzysecurity.com/tutorials/expDev/16.html
  • https://www.fuzzysecurity.com/tutorials/expDev/17.html
  • https://www.fuzzysecurity.com/tutorials/expDev/18.html
  • https://www.fuzzysecurity.com/tutorials/expDev/19.html
  • https://www.fuzzysecurity.com/tutorials/expDev/20.html
  • http://dokydoky.tistory.com/445
  • https://hshrzd.wordpress.com/2017/05/28/starting-with-windows-kernel-exploitation-part-1-setting-up-the-lab/
  • https://hshrzd.wordpress.com/2017/06/05/starting-with-windows-kernel-exploitation-part-2/
  • https://hshrzd.wordpress.com/2017/06/22/starting-with-windows-kernel-exploitation-part-3-stealing-the-access-token/
  • https://osandamalith.com/2017/04/05/windows-kernel-exploitation-stack-overflow/
  • https://osandamalith.com/2017/06/14/windows-kernel-exploitation-arbitrary-overwrite/
  • https://osandamalith.com/2017/06/22/windows-kernel-exploitation-null-pointer-dereference/
  • http://dali-mrabet1.rhcloud.com/windows-kernel-exploitation-arbitrary-memory-overwrite-hevd-challenges/
  • https://blahcat.github.io/2017/08/31/arbitrary-write-primitive-in-windows-kernel-hevd/
  • https://klue.github.io/blog/2017/09/hevd_stack_gs/
  • https://glennmcgui.re/introduction-to-windows-kernel-exploitation-pt-1/
  • https://glennmcgui.re/introduction-to-windows-kernel-driver-exploitation-pt-2/
  • https://kristal-g.github.io/2021/02/07/HEVD_StackOverflowGS_Windows_10_RS5_x64.html
  • https://kristal-g.github.io/2021/02/20/HEVD_Type_Confusion_Windows_10_RS5_x64.html
  • https://wafzsucks.medium.com/hacksys-extreme-vulnerable-driver-arbitrary-write-null-new-solution-7d45bfe6d116
  • https://wafzsucks.medium.com/how-a-simple-k-typeconfusion-took-me-3-months-long-to-create-a-exploit-f643c94d445f
  • https://mdanilor.github.io/posts/hevd-0/
  • https://mdanilor.github.io/posts/hevd-1/
  • https://mdanilor.github.io/posts/hevd-2/
  • https://mdanilor.github.io/posts/hevd-3/
  • https://mdanilor.github.io/posts/hevd-4/