Talk:DoublePulsar
Add topic| This article is rated Stub-class on Wikipedia's content assessment scale. It is of interest to the following WikiProjects: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Zero Day Vulnerability
[edit]This malware uses a fault (of which their are many) when emulating MS DOS. In Virtual mode (as apposed to real), the monitor cannot spot self-modifying code allowing a TSR to hook into the real (ring-0) kernal vectors. The action of reading a 16-bit number from address $ffff works on an 8086, 80186 and 80386 BUT crashes in 80286. To emulate MS DOS programs, the monitor has to emulate how different cores reacted. The length of ignore.dll in Wannacry and analysis of this file shows that the file itself and the 16K NTWINKR.exe file it downloads are identical. — Preceding unsigned comment added by 81.99.74.135 (talk) 21:11, 13 June 2017 (UTC)
- Stub-Class Crime-related articles
- Low-importance Crime-related articles
- WikiProject Crime and Criminal Biography articles
- Stub-Class Computing articles
- Low-importance Computing articles
- Stub-Class Computer networking articles
- Low-importance Computer networking articles
- Stub-Class Computer networking articles of Low-importance
- All Computer networking articles
- Stub-Class software articles
- Low-importance software articles
- Stub-Class software articles of Low-importance
- All Software articles
- Stub-Class Computer security articles
- High-importance Computer security articles
- Stub-Class Computer security articles of High-importance
- All Computer security articles
- All Computing articles
- Stub-Class Internet articles
- Low-importance Internet articles
- WikiProject Internet articles
- Stub-Class United States articles
- Low-importance United States articles
- Stub-Class United States articles of Low-importance
- WikiProject United States articles


