https://github.com/hacksysteam/HackSysExtremeVulnerableDriver
HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
https://github.com/hacksysteam/HackSysExtremeVulnerableDriver
buffer-overflow driver exploit-development exploitation hevd info-leak kernel linux memory-corruption type-confusion uaf vulnerabilities windows
Last synced: 5 days ago
JSON representation
HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
- Host: GitHub
- URL: https://github.com/hacksysteam/HackSysExtremeVulnerableDriver
- Owner: hacksysteam
- License: gpl-3.0
- Created: 2015-05-28T08:24:56.000Z (almost 10 years ago)
- Default Branch: master
- Last Pushed: 2024-02-03T09:13:11.000Z (about 1 year ago)
- Last Synced: 2024-05-18T21:56:02.357Z (11 months ago)
- Topics: buffer-overflow, driver, exploit-development, exploitation, hevd, info-leak, kernel, linux, memory-corruption, type-confusion, uaf, vulnerabilities, windows
- Language: C
- Homepage: https://hacksys.io
- Size: 1.75 MB
- Stars: 2,337
- Watchers: 96
- Forks: 522
- Open Issues: 14
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING.md
- License: LICENSE
Awesome Lists containing this project
- jimsghstars - hacksysteam/HackSysExtremeVulnerableDriver - HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux (C)
- awesome-hacking-lists - hacksysteam/HackSysExtremeVulnerableDriver - HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux (C)
README
# HackSys Extreme Vulnerable Driver
ooooo ooooo oooooooooooo oooooo oooo oooooooooo.
`888' `888' `888' `8 `888. .8' `888' `Y8b
888 888 888 `888. .8' 888 888
888ooooo888 888oooo8 `888. .8' 888 888
888 888 888 " `888.8' 888 888
888 888 888 o `888' 888 d88'
o888o o888o o888ooooood8 `8' o888bood8P'------------------------------------------------------------------------
[](https://www.blackhat.com/asia-16/arsenal.html#hacksys-extreme-vulnerable-driver)
[](https://ci.appveyor.com/project/hacksysteam/hacksysextremevulnerabledriver/branch/master)
[](https://github.com/hacksysteam/HackSysExtremeVulnerableDriver/releases)
[](https://twitter.com/HackSysTeam)
[](https://infosec.exchange/@hacksysteam)
[](https://discord.com/invite/ns32uNhaq7)The **HackSys Extreme Vulnerable Driver (HEVD)** is a **Windows Kernel** driver that is intentionally vulnerable. It has been developed for **security researchers** and **enthusiasts** to improve their skills in **kernel-level** exploitation.
**HEVD** offers a range of vulnerabilities, from simple **stack buffer overflows** to more complex issues such as **use-after-free**, **pool buffer overflows**, and **race conditions**. This allows researchers to explore exploitation techniques for each implemented vulnerability.
## Black Hat Arsenal 2016
* [Presentation](https://www.blackhat.com/docs/asia-16/materials/arsenal/asia-16-Ansari-HackSys-Extreme-Vulnerable-Driver.pdf)
* [White Paper](https://www.blackhat.com/docs/asia-16/materials/arsenal/asia-16-Ansari-HackSys-Extreme-Vulnerable-Driver-wp.pdf)## Blog Post
*
## External Exploits
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*## External Blog Posts
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*## Author
> **Ashfaq Ansari**
> ashfaq[at]hacksys[dot]io
> **[Blog](https://hacksys.io/ "HackSys Team") | [@HackSysTeam](https://twitter.com/HackSysTeam)**
> [](https://hacksys.io)
> [https://hacksys.io/](https://hacksys.io/ "HackSys Inc")
## Screenshots




## Vulnerabilities Implemented
* **Write NULL**
* **Double Fetch**
* **Buffer Overflow**
* **Stack**
* **Stack GS**
* **NonPagedPool**
* **NonPagedPoolNx**
* **PagedPoolSession**
* **Use After Free**
* **NonPagedPool**
* **NonPagedPoolNx**
* **Type Confusion**
* **Integer Overflow**
* **Arithmetic Overflow**
* **Memory Disclosure**
* **NonPagedPool**
* **NonPagedPoolNx**
* **Arbitrary Increment**
* **Arbitrary Overwrite**
* **Null Pointer Dereference**
* **Uninitialized Memory**
* **Stack**
* **NonPagedPool**
* **Insecure Kernel Resource Access**## Building the driver
1. [Install Visual Studio 2017](https://visualstudio.microsoft.com/downloads/)
2. [Install Windows Driver Kit](https://docs.microsoft.com/en-us/windows-hardware/drivers/download-the-wdk)
3. Run the appropriate driver builder `Build_HEVD_Vulnerable_x86.bat` or `Build_HEVD_Vulnerable_x64.bat`## Download
If you do not want to build **HackSys Extreme Vulnerable Driver** from source, you could download pre-built
executables for the latest release:[https://github.com/hacksysteam/HackSysExtremeVulnerableDriver/releases](https://github.com/hacksysteam/HackSysExtremeVulnerableDriver/releases)
## Installing the driver
Use [OSR Driver Loader](https://www.osronline.com/article.cfm?article=157) to install **HackSys Extreme Vulnerable Driver**
## Testing
The **HackSys Extreme Vulnerable Driver** and the respective exploits have been tested on **Windows 7 SP1 x86** and **Windows 10 x64**
## Sessions Conducted
* [Windows Kernel Exploitation 1](http://null.co.in/event_sessions/156-windows-kernel-exploitation)
* [Windows Kernel Exploitation 2](http://null.co.in/event_sessions/186-windows-kernel-exploitation-2)
* [Windows Kernel Exploitation 3](http://null.co.in/event_sessions/226-windows-kernel-exploitation-3)
* [Windows Kernel Exploitation 4](http://null.co.in/event_sessions/234-windows-kernel-exploitation-4)
* [Windows Kernel Exploitation 5](http://null.co.in/event_sessions/309-windows-kernel-exploitation-5)
* [Windows Kernel Exploitation 6](https://null.co.in/event_sessions/482-windows-kernel-exploitation-6)
* [Windows Kernel Exploitation 7](https://null.co.in/event_sessions/845-windows-kernel-exploitation-7)## Workshops Conducted
* [Windows Kernel Exploitation Humla Pune](http://null.co.in/event_sessions/280-windows-kernel-exploitation)
* [Windows Kernel Exploitation Humla Mumbai](http://null.co.in/event_sessions/327-windows-kernel-exploitation)## HEVD for Linux




## License
Please see the file `LICENSE` for copying permission
## Contribution Guidelines
Please see the file `CONTRIBUTING.md` for contribution guidelines
## TODO & Bug Reports
Please file any enhancement request or bug report via the **GitHub** issue tracker at the below-given address: [https://github.com/hacksysteam/HackSysExtremeVulnerableDriver/issues](https://github.com/hacksysteam/HackSysExtremeVulnerableDriver/issues)
## Acknowledgments
Thanks go to these wonderful people: 🎉
------------------------------------------------------------------------
[](https://hacksys.io)