Results 1 to 8 of 8
  1. #1
    Join Date
    Jul 2008
    Location
    Gloucester
    Posts
    976
    Tokens
    0

    Default Windows Vista security 'rendered useless' by researchers

    Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. have discovered a technique that can be used to bypass all memory protection safeguards that Microsoft built into Windows Vista. These new methods have been used to get around Vista's Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP) and other protections by loading malicious content through an active web browser. The researchers were able to load whatever content they wanted into any location they wished on a user's machine using a variety of objects, such as Java, ActiveX and even .NET objects. This feat was achieved by taking advantage of the way that Internet Explorer (and other browsers) handle active scripting in the Operating System.

    While this may seem like any standard security hole, other researchers say that the work is a major breakthrough and there is very little that Microsoft can do to fix the problems. These attacks work differently than other security exploits, as they aren't based on any new Windows vulnerabilities, but instead take advantage of the way Microsoft chose to guard Vista's fundamental architecture. According to Dino Dai Zovi, a popular security researcher, "the genius of this is that it's completely reusable. They have attacks that let them load chosen content to a chosen location with chosen permissions. That's completely game over."

    According to Microsoft, many of the defenses added to Windows Vista (and Windows Server 2008) were added to stop all host-based attacks. For example, ASLR is meant to stop attackers from predicting key memory addresses by randomly moving a process' stack, heap and libraries. While this technique is very useful against memory corruption attacks, it would be rendered useless against Dowd and Sotirov's new method. "This stuff just takes a knife to a large part of the security mesh Microsoft built into Vista," said Dai Zovi to SearchSecurity.com. "If you think about the fact that .NET loads DLLs into the browser itself and then Microsoft assumes they're safe because they're .NET objects, you see that Microsoft didn't think about the idea that these could be used as stepping stones for other attacks. This is a real tour de force."

    While Microsoft hasn't officially responded to the findings, Mike Reavey, group manager of the Microsoft Security Response Center, said the company has been aware of the research and is very interested to see it once it has been made public. It currently isn't known whether these exploits can be used against older Microsoft Operating Systems, such as Windows XP and Windows Server 2003, but since these techniques do not rely on any one specific vulnerability, Zovi believes that we may suddenly see many similar techniques applied to other platforms or environments. "This is not insanely technical. These two guys are capable of the really low-level technical attacks, but this is simple and reusable," Dai Zovi said. "I definitely think this will get reused soon."
    tl;dr lolvista

    More





  2. #2
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    Why don't they ever post proof? -.-
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

  3. #3
    Join Date
    Dec 2006
    Location
    Nottingham
    Posts
    7,752
    Tokens
    756
    Habbo
    katie.pricejorda

    Latest Awards:

    Default

    It's not really surprising though, everyone knows that Vista is vulnerable that's why nearly everyone uses an Anti-Virus, they don't just use an AV because they want to, we use an AV because we know Windows isn't secure, it doesn't take some IBM Wizards to tell you that.

  4. #4
    Join Date
    Jul 2008
    Location
    Gloucester
    Posts
    976
    Tokens
    0

    Default

    Quote Originally Posted by Jordy View Post
    It's not really surprising though, everyone knows that Vista is vulnerable that's why nearly everyone uses an Anti-Virus, they don't just use an AV because they want to, we use an AV because we know Windows isn't secure, it doesn't take some IBM Wizards to tell you that.
    I don't think Anti-Virus programs check .NET content either though as they'd assume it's trusted too.

    Quote Originally Posted by Tawm View Post
    Why don't they ever post proof? -.-
    It's not like they can say "here look at this code: this is why it's flawed", this is about how the OS is coded lol.
    Last edited by DrLacero; 11-08-2008 at 05:59 PM.





  5. #5
    Join Date
    Jul 2004
    Location
    UK
    Posts
    23,590
    Tokens
    33,601
    Habbo
    xxMATTGxx

    Latest Awards:

    Default

    Yeah when I run windows, which is very rare these days I always had an Anti-virus installed because i just didn't trust the system.


    Previous Habbox Roles
    Co-Owner of Habbox | General Manager | Assistant General Manager (Staff) | Forum Manager | Super Moderator | Forum Moderator

  6. #6
    Join Date
    Dec 2005
    Posts
    2,992
    Tokens
    1,531

    Latest Awards:

    Default

    Quote Originally Posted by Tawm View Post
    Why don't they ever post proof? -.-
    They're not going to lie, lol. Plus it's not like on a forum when you need proof for everything that happens to you in life. "I feel over today" "Pics or it didn't happen"
    That went fast.

  7. #7
    Join Date
    Jul 2004
    Location
    UK
    Posts
    23,590
    Tokens
    33,601
    Habbo
    xxMATTGxx

    Latest Awards:

    Default

    Quote Originally Posted by Tawm View Post
    Why don't they ever post proof? -.-
    Go and download some nice Viruses without any Anti-Virus and have some fun


    Previous Habbox Roles
    Co-Owner of Habbox | General Manager | Assistant General Manager (Staff) | Forum Manager | Super Moderator | Forum Moderator

  8. #8
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    Already did

    Sometimes they post videos of them actually doing some damage.
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •