There do not seem to be any mentions of the driver blacklist in c:\windows\appPatch\drvmain.sdb online. Lets change that! It gets enabled with "isolated core" functionality. To bypass it- replace it with this old version: https://cdn.discordapp.com/attachments/794460959615090712/807965504161054740/drvmain.sdb …
-
Show this thread
-
I can be wrong about this- but maybe "\SystemRoot\AppPatch\drvpatch.sdb" is undocumented ring0 arb write? somebody should check :)
1 reply 0 retweets 9 likesShow this thread -
-
Replying to @aionescu
Well- you are it security version of "the simpsons already did it" so I am not gonna let that stop me :) What about the new version of dtrace- that should be using hypervisor. I am quite confused about whats going on there- if you get bored or something :)
1 reply 0 retweets 0 likes -
Replying to @jonasLyk
I’m not telling you to stop. I’m just saying this is old news. See screenshot.pic.twitter.com/poXvqRz5Rx
1 reply 0 retweets 0 likes -
You claimed “no mention of this online”, that’s just patently false. I also gave a talk (available online) about the kernel shim database. Additionally, @geoffchappell has loads of information on it.
2 replies 0 retweets 4 likes
umm I am talking about it containing a list of drivers that will not load when you enable "isolated core" not its normal shimming capacity
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.