PaulSpoerry.com

You found me… insights on technology, philosophy, Windows, hacking and more.
  • rss
  • Home
  • Archive
  • Links
  • Contact
  • Categories
  • Search
  • Snazzy Archives
  • About
  • Photos

Unstoppable Vista Hack Created

August 11, 2008

In a presentation at the Black Hat briefings, Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. will discuss the new methods they’ve found to get around Vista protections such as Address Space Layout Randomization(ASLR), Data Execution Prevention (DEP) and others. Essentially they’ve figured out a way to hack Vista using Java, ActiveX controls and .NET objects to load arbitrary content into Web browsers.

What they are indicating is that they have revealed a fatal flaw in Windows Vista which potentially blows the OS wide open and in such a way that it cannot be fixed. The attacks themselves are not based on any new vulnerabilities in IE or Vista, but instead take advantage of Vista’s fundamental architecture and the ways in which Microsoft chose to protect it.

Many of the defenses that Microsoft added to Vista and Windows Server 2008 are designed to stop host-based attacks. ASLR, for example, is meant to prevent attackers from predicting target memory addresses by randomly moving things such as a process’s stack, heap and libraries. That technique is useful against memory-corruption attacks, but Dai Zovi said that against Dowd’s and Sotirov’s methods, it would be of no use.

“This stuff just takes a knife to a large part of the security mesh Microsoft built into Vista,” Dai Zovi said. “If you think about the fact that .NET loads DLLs into the browser itself and then Microsoft assumes they’re safe because they’re .NET objects, you see that Microsoft didn’t think about the idea that these could be used as stepping stones for other attacks. This is a real tour de force.”

They go on to imply the approach can also potentially be applied to other operating systems such as Windows XP and Mac OSX (but not with this specific technique).

Read more at TechTarget or TrustedReviews

Comments
No Comments »
Categories
Code, Hacking, Tech, Windows
Tags
address space, Address Space Layout Randomization, ASLR, attackers, black hat briefings, data execution prevention, DEP, fundamental architecture, hacking vista, IBM Internet Security Systems, internet security systems, iss, memory addresses, memory corruption, randomization, stepping stones, target memory, using java, vista hack, vmware, vulnerabilities, web browsers, windows server
Comments rss Comments rss
Trackback Trackback

How to Try Ubuntu without Leaving Windows

July 17, 2008

Ubuntu would be neat to try, but for many of us, having to leave Windows and boot into a whole different operating system is a full day project.

Nerdbusiness created this tutorial. So you don’t have to leave Windows to try ubuntu. I’ll be showing you how to setup a “virtual machine” inside Windows that will run Ubuntu inside a tidy little window. So you can launch it from the Start Bar. And have Ubuntu running in the background just like any other Windows program like the internet browser or your game of solitaire.

Above: Having Ubuntu running inside Windows is just cool. Plus, its a great way to try out all of Ubuntus features .

Having Ubuntu running inside Windows is just cool. Plus, it's a great way to try out all of Ubuntu's features

Read the rest of this entry �

Comments
1 Comment »
Categories
Linux, Tech, Windows
Tags
game, internet browser, Linux, operating system, ubuntu, ubuntu in vm, virtual machine, vmware, windows program
Comments rss Comments rss
Trackback Trackback

Google Search

Tag Cloud

ajax amazon barack obama bittorrent blog firefox Gadgets game Gmail google Google Chrome HTC HTC Touch humor iGoogle john mccain launch Linux menu search microsoft microsoft windows Mozilla Firefox open source operating system Politics Religion Ron Paul sprint Sprint Touch start menu tabs target united states user interface video Vista vista tweak Vista Tweaks wikipedia Windows Windows Mobile windows vista windows xp Wordpress youtube

Onlywire

rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox