Vista Blown Open By Unstoppable Hack
| Author | Gordon Kelly |
| Published | 10th Aug 2008 |
Comments for Vista Blown Open By Unstoppable Hack
Wackywavinginflateablearmflailingtubeman said on 11th August 2008
Azro said on 11th August 2008
"Vista Blown Open By Unstoppable Hack"
Oops.
"The approach can also potentially be applied to other operating systems such as Windows XP and Mac OS X."
Oh no. Nevermind!
ilovethemonkeyhead said on 11th August 2008
ouch...
i'm fast loosing faith in windows vista, now...
The Mighty Ben said on 11th August 2008
Never leave your Windows open - a burglar might get in.
Stephen Allred said on 11th August 2008
"The approach can also potentially be applied to other operating systems such as Windows XP and Mac OS X."
Mac OS X doesn't have a .NET virtual machine, and is a completely different design, with a different kernel and ecosystem to Windows, so I really doubt that claim. Shockingly, being a completely different operating system, OSX doesn't use either Vista's Address Space Layout Randomization (ASLR) (it uses randomization of some library offsets in 10.5 and above) or Data Execution Prevention (DEP) technologies. If, however, it is true, every BSD, and the Linux kernel and it's derivatives would be equally as vulnerable.
Gordon said on 11th August 2008
@Stephen - I believe the phrase: "can also potentially be applied to" means just that. The full details have not been made public yet but obviously it won't use .NET, best you hold off and wait for its publishing so you can make an informed verdict.
howiem said on 11th August 2008
Why do these articles always seem to focus on the threat and not on the means of protection? In other words, what actions should Vista users be taking to mitigate the threat.
Gordon said on 11th August 2008
@howiem - for now the hint is in the title... nothing can be done.
RafflesNH said on 11th August 2008
Is this the 'full details' you mention Gordon?
http://taossa.com/archive/bh08sotirovdowd.pdf (53 pages) written 7th August.
The final paragraph in the authors' concluding statement reads:
"The authors expect these problems to be addressed in future releases of Windows and browser plugins shipped by third parties."
So not really the 'Unstoppable hack', surely?
howiem said on 11th August 2008
Gordon, are you saying that firewalls, HIPs and other protection will not do anything?
Gordon said on 11th August 2008
@howiem, no idea at this stage - we're waiting for the full details to go public. Either way, it's worrying...
howiem said on 11th August 2008
You might want to look at Ed Bott's article over at http://blogs.zdnet.com/Bott/?p=512
dworvos said on 11th August 2008
@Stephen Allred
Data Execution Prevention (DEP) is a good thing if used correctly (which is supported at the hardware level by a XD bit), the fact that OS X doesn't use it makes me question the security of the OS. Security is based on the weakest link so if there are no other avenues of attack, this one will remain open. Unfortunately, Apple does not go the route of Microsoft and disclose their bugs, Apple denies there are bugs in their OS and then fixes them quietly. Here's a site of someone who found a bug a day for a month in 2007. http://projects.info-pull.com/moab/
Azro said on 12th August 2008
Alex Sotirov responds to Ed Bott's ZDnet's blog: "Thanks for your blog post about our research. I was horrified by the lack of understanding displayed by the tech press when they covered the paper Mark and I presented at BlackHat. You rightly point out that the sky is not falling and the flaws are not unfixable. In fact, the next versions of Flash and Java will contain specific measures that limit the impact of the techniques we presented. We expect Microsoft to follow suit as well.
Exploitation is a cat and mouse game. The paper we presented puts the offensive side at a slight advantage, but it won’t take long for the defenses to catch up. Our intention was always to nudge the software vendors into improving their defenses and I hope we will succeed."
Just a storm in a tea cup then? http://blogs.zdnet.com/Bott/?p=513
Stephen Allred said on 12th August 2008
@dworvos
Did I say OSX didn't use the No eXecute (or eXecute Disable, as Intel have decided to market it) bit? No. I said OSX doesn't use the Vista's (and by that token XP's) implementation of it, which Microsoft have helpfully dubbed DEP (which, you may like to note, is by default only active on essential OS processes).
You think Microsoft discloses it's bugs? More fool you. As for the bug a day for a month, that's 31 bugs in a modern OS. That's really not surprising.
Chani Tough said on 13th August 2008
Windows are a pane
Add Your Comment
Add your comment
You must be logged in to comment. Login or register here.


"Vista Blown Open By Unstoppable Hack "
Why am I not surprised..?
Ubuntu is looking pretty good lately...