PaulSpoerry.com

You found me… insights on technology, philosophy, Windows, hacking and more.
  • rss
  • Home
  • Archive
  • Links
  • Contact
  • Categories
  • Search
  • Snazzy Archives
  • About
  • Photos

Unstoppable Vista Hack Created

August 11, 2008

In a presentation at the Black Hat briefings, Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. will discuss the new methods they’ve found to get around Vista protections such as Address Space Layout Randomization(ASLR), Data Execution Prevention (DEP) and others. Essentially they’ve figured out a way to hack Vista using Java, ActiveX controls and .NET objects to load arbitrary content into Web browsers.

What they are indicating is that they have revealed a fatal flaw in Windows Vista which potentially blows the OS wide open and in such a way that it cannot be fixed. The attacks themselves are not based on any new vulnerabilities in IE or Vista, but instead take advantage of Vista’s fundamental architecture and the ways in which Microsoft chose to protect it.

Many of the defenses that Microsoft added to Vista and Windows Server 2008 are designed to stop host-based attacks. ASLR, for example, is meant to prevent attackers from predicting target memory addresses by randomly moving things such as a process’s stack, heap and libraries. That technique is useful against memory-corruption attacks, but Dai Zovi said that against Dowd’s and Sotirov’s methods, it would be of no use.

“This stuff just takes a knife to a large part of the security mesh Microsoft built into Vista,” Dai Zovi said. “If you think about the fact that .NET loads DLLs into the browser itself and then Microsoft assumes they’re safe because they’re .NET objects, you see that Microsoft didn’t think about the idea that these could be used as stepping stones for other attacks. This is a real tour de force.”

They go on to imply the approach can also potentially be applied to other operating systems such as Windows XP and Mac OSX (but not with this specific technique).

Read more at TechTarget or TrustedReviews

Comments
No Comments »
Categories
Code, Hacking, Tech, Windows
Tags
address space, Address Space Layout Randomization, ASLR, attackers, black hat briefings, data execution prevention, DEP, fundamental architecture, hacking vista, IBM Internet Security Systems, internet security systems, iss, memory addresses, memory corruption, randomization, stepping stones, target memory, using java, vista hack, vmware, vulnerabilities, web browsers, windows server
Comments rss Comments rss
Trackback Trackback

Google Search

Tag Cloud

ajax amazon barack obama bittorrent blog firefox Gadgets game Gmail google Google Chrome HTC HTC Touch humor iGoogle john mccain launch Linux menu search microsoft microsoft windows Mozilla Firefox open source operating system Politics Religion Ron Paul sprint Sprint Touch start menu tabs target united states user interface video Vista vista tweak Vista Tweaks wikipedia Windows Windows Mobile windows vista windows xp Wordpress youtube

Onlywire

rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox