Curb Zone
 
   
 

Go Back   Curb Zone > TechTalk > Computers & Programming

Computers & Programming General Questions, Hardware Reviews, Programming, etc.


Welcome to the Curb Zone.

You are currently viewing our site as a guest which gives you limited access to view and access most features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!
.
Reply
 
LinkBack Thread Tools Display Modes
Old 08-07-2006, 02:36 PM   #1 (permalink)
Global Moderator
 
Mikael's Avatar
 
Join Date: Nov 2005
Posts: 1,849
Thanks: 767
Thanked 321 Times in 205 Posts
Mikael is a glorious beacon of lightMikael is a glorious beacon of lightMikael is a glorious beacon of lightMikael is a glorious beacon of lightMikael is a glorious beacon of light
Vista hacked already!

Vista hacked at Black Hat


By Joris Evers, CNET News.com
Published on ZDNet News: August 4, 2006, 1:34 PM PT

LAS VEGAS--While Microsoft talked up Windows Vista security at Black Hat, a researcher in another room demonstrated how to hack the operating system.

Joanna Rutkowska, a Polish researcher at Singapore-based Coseinc, showed that it is possible to bypass security measures in Vista that should prevent unsigned code from running.

And in a second part of her talk, Rutkowska explained how it is possible to use virtualization technology to make malicious code undetectable, in the same way a rootkit does. She code-named this malicious software Blue Pill.

"Microsoft is investigating solutions for the final release of Windows Vista to help protect against the attacks demonstrated," a representative for the software maker said. "In addition, we are working with our hardware partners to investigate ways to help prevent the virtualization attack used by the Blue Pill."

At Black Hat, Microsoft gave out copies of an early Vista release for attendees to test. The software maker is still soliciting feedback on the successor to Windows XP, which is slated to be broadly available in January.

Rutkowska's presentation filled a large ballroom at Caesars Palace to capacity, even though it was during the last time slot on the final day of the annual Black Hat security confab here. She used an early test version of Vista for her research work.

As one of the security measures in Vista, Microsoft is adding a mechanism to block unsigned driver software to run on the 64-bit version of the operating system. However, Rutkowska found a way to bypass the shield and get her code to run. Malicious drivers could pose a serious threat because they run at a low level in the operating system, security experts have said.

"The fact that this mechanism was bypassed does not mean that Vista is completely insecure. It's just not as secure as advertised," Rutkowska said. "It's very difficult to implement a 100 percent-efficient kernel protection."

To stage the attack, however, Vista needs to be running in administrator mode, Rutkowska acknowledged. That means her attack would be foiled by Microsoft's User Account Control, a Vista feature that runs a PC with fewer user privileges. UAC is a key Microsoft effort to prevent malicious code from being able to do as much damage as on a PC running in administrator mode, a typical setting on Windows XP.

"I just hit accept," Rutkowska replied to a question from the audience about how she bypassed UAC. Because of the many security pop-ups in Windows, many users will do the same without realizing what they are allowing, she said.

Microsoft has touted Vista as its most secure version of Windows yet. It is the first operating system client to go through the company's Security Development Lifecycle, a process to vet code and stamp out flaws before a product ships.

"Windows Vista has many layers of defense, including the firewall, running as a standard user, Internet Explorer Protected Mode, /NX support, and ASLR, which help prevent arbitrary code from running with administrative privileges," the Microsoft representative noted.

After the presentation on bypassing the driver shield, Rutkowska presented a way to create the stealthy malicious software she code-named Blue Pill. The technique uses Pacifica, a Secure Virtual Machine, from chipmaker Advanced Micro Devices, to go undetected.

Blue Pill could serve as a backdoor for attackers, Rutkowska said. While it was developed on Vista and AMD's technology, it should also work on other operating systems and hardware platforms. "Some people suggested that my work is sponsored by Intel, as I focused on AMD virtualization technology only," she said, adding that is untrue.
Mikael is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Advertisement
 
Advertisement
Sponsored links

Reply

Bookmarks
Search Cloud
2009 a4 cabriolet 2009 honda s2000 2009 hyundai tiburon 2010 audi a3 2010 rolls royce 350z hp a3 2010 adenauer mercedes adriana stoner adriana stoner photos adriana stoner pictures amx07 audi 2009 a4 audi a3 2010 audi a3 titanium audi a7 audi brand core values audi forum tokyo audi mmi interface cable audi mmi ipod audi q7 wallpaper audi q7 wallpapers b6 rs4 conversion bentley brunei bf 109 wallpaper bmw 5er f10 boeing 2707 boeing sst bombardier bike bombardier spyder buy iphone switzerland c clas cdi car photography tutorial cool shark photos cool shark pictures croatian chicks croatian girls croatian hot girls curbzone damien hirst's controversial skull dc-xz6 donald trump mansion donald trump's mansion female music artists follow me car future supercars gl63 gl63 amg grey goose rolls royce phantom hot croatian girl hot croatian girls hot croatians hyundai 2009 tiburon hyundai tiburon 2009 iphone 3g prepaid switzerland koenigsegg car configurator koenigsegg configurator madtv sketches mercedes mixte mmi ipod modified x5 monet motertrend new audi a3 2010 new slk 2009 nurburgring wallpapers price waleed q7 body kit richest f1 drivers rims configurator ruji wallpaper salma hayek video seat ibiza 2009 secret service suv secret service vehicles sl55 body kit slk 2009 spyder motercycle sr71 replacement stoner adriana sultan of brunei car sultan of brunei cars swallow chicken bone swallowed chicken bone the resolute desk top gayer top gear s5 traveler dc xz6 traveler dc-xz6 trump houses v!sa gmi+calibration+manual vectoring quattro system vepr commander versace aircraft volkswagen phaeton reliability vroom box waleed diamond mercedes what is eaten in one week www.curbzone.com z350 2005 for sale uae

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista Bèta 2 RikfromBelgium Computers & Programming 9 06-13-2006 08:55 PM


All times are GMT -5. The time now is 08:13 PM.