gfxgfx
 
Please login or register.

Login with username, password and session length
 
gfx gfx
gfx
76793 Posts in 13502 Topics by 1651 Members - Latest Member: Arnold99 November 25, 2024, 09:33:36 am
*
gfx*gfx
gfx
WinMX World :: Forum  |  Discussion  |  WinMx World News  |  Vista's Security Rendered Useless
gfx
gfxgfx
 

Author Topic: Vista's Security Rendered Useless  (Read 645 times)

0 Members and 1 Guest are viewing this topic.

Offline GhostShip

  • Ret. WinMX Special Forces
  • WMW Team
  • *****
Vista's Security Rendered Useless
« on: August 10, 2008, 08:14:15 am »
As expected folks ..

http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324395,00.html

Quote
Two security researchers have developed a new technique that essentially bypasses all of the memory protection safeguards in the Windows Vista operating system, an advance that many in the security community say will have far-reaching implications not only for Microsoft, but also on how the entire technology industry thinks about attacks.

In a presentation at the Black Hat briefings, Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. will discuss the new methods they've found to get around Vista protections such as Address Space Layout Randomization(ASLR), Data Execution Prevention (DEP) and others by using Java, ActiveX controls and .NET objects to load arbitrary content into Web browsers.

By taking advantage of the way that browsers, specifically Internet Explorer, handle active scripting and .NET objects, the pair have been able to load essentially whatever content they want into a location of their choice on a user's machine.

Researchers who have read the paper that Dowd and Sotirov wrote on the techniques say their work is a major breakthrough and there is little that Microsoft can do to address the problems.

The more layers of protection added to a program means simply there is more likely to be a targetted attack on it and in this case an attack thats likely to embaress a few "experts" at microsoft.

Offline White Stripes

  • Core
  • *****
  • ***
  • Je suis aimé
Re: Vista's Security Rendered Useless
« Reply #1 on: August 12, 2008, 06:22:08 pm »
java will have this problem fixed (sun microsystems version anyway.. it just may take them a while..) but when one -embeds- a browser into an OS there -is- no way to secure it....

WinMX World :: Forum  |  Discussion  |  WinMx World News  |  Vista's Security Rendered Useless
 

gfxgfx
gfx
©2005-2024 WinMXWorld.com. All Rights Reserved.
SMF 2.0.19 | SMF © 2021, Simple Machines | Terms and Policies
Page created in 0.008 seconds with 22 queries.
Helios Multi © Bloc
gfx
Powered by MySQL Powered by PHP Valid XHTML 1.0! Valid CSS!