Reply

Join Date: Aug 2005
Posts: 15,151
Reputation: Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute Ancient Dragon has a reputation beyond repute 
Solved Threads: 1435
Team Colleague
Featured Poster
Ancient Dragon's Avatar
Ancient Dragon Ancient Dragon is offline Offline
Most Valuable Poster

Oops!

 
0
  #1
Aug 9th, 2008
Vista security rendered 'uselsess'
By Dennis Fisher

Two security researchers have developed a new technique that essentially bypasses all of the memory protection safeguards in the Windows Vista operating system, an advance that many in the security community say will have far-reaching implications not only for Microsoft, but also on how the entire technology industry thinks about attacks.

In a presentation at the Black Hat briefings, Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. will discuss the new methods they've found to get around Vista protections such as Address Space Layout Randomization(ASLR), Data Execution Prevention (DEP) and others by using Java, ActiveX controls and .NET objects to load arbitrary content into Web browsers.

By taking advantage of the way that browsers, specifically Internet Explorer, handle active scripting and .NET objects, the pair have been able to load essentially whatever content they want into a location of their choice on a user's machine.
Last edited by Ancient Dragon; Aug 9th, 2008 at 10:14 am.
Don't PM me with questions -- you might get a nasty PM in response. If you have a question then post it in one of the forums.
Reply With Quote Quick reply to this message  
Join Date: Dec 2005
Posts: 5,851
Reputation: Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute Salem has a reputation beyond repute 
Solved Threads: 749
Team Colleague
Salem's Avatar
Salem Salem is offline Offline
Void main'ers are DOOMed

Re: Oops!

 
0
  #2
Aug 9th, 2008
Well that's what you get when you integrate a browser into the OS.

http://www.answers.com/topic/hoare-c-a-r
Perhaps it's time to consider making things much simpler, rather than bloating the crap out of everything in the guise of creating "value".

Or as Scotty in ST-III said "The more they over think the plumbing, the easier it is to stop up the drain."
Or in this case find, yet another hole which leaks
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 19
Reputation: xxxviking is an unknown quantity at this point 
Solved Threads: 0
xxxviking xxxviking is offline Offline
Newbie Poster

Re: Oops!

 
0
  #3
Aug 10th, 2008
yess.. greatt!! one.. i too hae same thinking..
Last edited by ~s.o.s~; Aug 11th, 2008 at 1:19 pm. Reason: Fake signature.
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 2,275
Reputation: sneekula has a spectacular aura about sneekula has a spectacular aura about 
Solved Threads: 174
sneekula's Avatar
sneekula sneekula is offline Offline
Nearly a Posting Maven

Re: Oops!

 
0
  #4
Aug 10th, 2008
Time to put the death penalty on evil-minded hackers!

In my mind they are nothing but terrorists, out there to do the most damage they can.
Last edited by sneekula; Aug 10th, 2008 at 11:36 am.
No one died when Clinton lied.
Reply With Quote Quick reply to this message  
Join Date: Feb 2007
Posts: 1,598
Reputation: scru has a spectacular aura about scru has a spectacular aura about 
Solved Threads: 130
Featured Poster
scru's Avatar
scru scru is offline Offline
Posting Virtuoso

Re: Oops!

 
0
  #5
Aug 10th, 2008
I hope you are kidding
Reply With Quote Quick reply to this message  
Join Date: Nov 2007
Posts: 978
Reputation: mitrmkar is just really nice mitrmkar is just really nice mitrmkar is just really nice mitrmkar is just really nice mitrmkar is just really nice 
Solved Threads: 208
mitrmkar mitrmkar is offline Offline
Posting Shark

Re: Oops!

 
0
  #6
Aug 10th, 2008
hmm, smells like hype, but let's see.
Reply With Quote Quick reply to this message  
Join Date: Aug 2008
Posts: 249
Reputation: mackone is on a distinguished road 
Solved Threads: 3
mackone mackone is offline Offline
Posting Whiz in Training

Re: Oops!

 
0
  #7
Aug 11th, 2008
It could be a hype as they say their findings which could completely bring Windows Vista to its knees. The researchers were able to load whatever content they wanted into any location they wished on a user.
Reply With Quote Quick reply to this message  
Join Date: Dec 2005
Posts: 3,224
Reputation: The Dude will become famous soon enough The Dude will become famous soon enough 
Solved Threads: 25
The Dude's Avatar
The Dude The Dude is offline Offline
Nearly a Senior Poster
 
0
  #8
Aug 11th, 2008
Its best to surf WITH SCRIPTS DISABLED (@ least in the INTERNET zone (If not the MY COMPUTER zone also)) Then they have a hard time executing anything from thier end.......
Last edited by The Dude; Aug 11th, 2008 at 5:19 pm.
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 850
Reputation: R0bb0b is on a distinguished road 
Solved Threads: 67
R0bb0b's Avatar
R0bb0b R0bb0b is offline Offline
Practically a Posting Shark

Re: Oops!

 
0
  #9
Aug 11th, 2008
No, you know what's going to happen, they are going to handle it just like they handle every other security issue. By turning it off. Then the rest of the development world will suffer.
Last edited by R0bb0b; Aug 11th, 2008 at 5:48 pm.
“Be who you are and say what you feel because those who mind don't matter and those who matter don't mind.” - Dr. Seuss

-- The documentation is inevitable, you may get away with it for a little while but eventually you too will have to do the deed.
Reply With Quote Quick reply to this message  
Join Date: Dec 2005
Posts: 3,224
Reputation: The Dude will become famous soon enough The Dude will become famous soon enough 
Solved Threads: 25
The Dude's Avatar
The Dude The Dude is offline Offline
Nearly a Senior Poster

Re: Oops!

 
0
  #10
Aug 12th, 2008
Maybe you can re-enable it in your copy
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Geeks' Lounge Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC