German Car Zone
Home
Go Back   German Car Zone > Website Forums > Off Topic > Computers
Reload this Page Vista hacked already!
Computers General Questions, Hardware Reviews, Programming, etc.

Notices
Reply
 
LinkBack Thread Tools Display Modes
  (#1 (permalink)) Old
bmer   bmer is online now
Devotee
 
bmer's Avatar
 
Posts: 4,447
Join Date: Nov 2005
Thanks: 4,282
Thanked 1,536 Times in 891 Posts
bmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud ofbmer has much to be proud of
Vista hacked already! - 08-07-2006, 04:36 PM

Vista hacked at Black Hat


By Joris Evers, CNET News.com
Published on ZDNet News: August 4, 2006, 1:34 PM PT

LAS VEGAS--While Microsoft talked up Windows Vista security at Black Hat, a researcher in another room demonstrated how to hack the operating system.

Joanna Rutkowska, a Polish researcher at Singapore-based Coseinc, showed that it is possible to bypass security measures in Vista that should prevent unsigned code from running.

And in a second part of her talk, Rutkowska explained how it is possible to use virtualization technology to make malicious code undetectable, in the same way a rootkit does. She code-named this malicious software Blue Pill.

"Microsoft is investigating solutions for the final release of Windows Vista to help protect against the attacks demonstrated," a representative for the software maker said. "In addition, we are working with our hardware partners to investigate ways to help prevent the virtualization attack used by the Blue Pill."

At Black Hat, Microsoft gave out copies of an early Vista release for attendees to test. The software maker is still soliciting feedback on the successor to Windows XP, which is slated to be broadly available in January.

Rutkowska's presentation filled a large ballroom at Caesars Palace to capacity, even though it was during the last time slot on the final day of the annual Black Hat security confab here. She used an early test version of Vista for her research work.

As one of the security measures in Vista, Microsoft is adding a mechanism to block unsigned driver software to run on the 64-bit version of the operating system. However, Rutkowska found a way to bypass the shield and get her code to run. Malicious drivers could pose a serious threat because they run at a low level in the operating system, security experts have said.

"The fact that this mechanism was bypassed does not mean that Vista is completely insecure. It's just not as secure as advertised," Rutkowska said. "It's very difficult to implement a 100 percent-efficient kernel protection."

To stage the attack, however, Vista needs to be running in administrator mode, Rutkowska acknowledged. That means her attack would be foiled by Microsoft's User Account Control, a Vista feature that runs a PC with fewer user privileges. UAC is a key Microsoft effort to prevent malicious code from being able to do as much damage as on a PC running in administrator mode, a typical setting on Windows XP.

"I just hit accept," Rutkowska replied to a question from the audience about how she bypassed UAC. Because of the many security pop-ups in Windows, many users will do the same without realizing what they are allowing, she said.

Microsoft has touted Vista as its most secure version of Windows yet. It is the first operating system client to go through the company's Security Development Lifecycle, a process to vet code and stamp out flaws before a product ships.

"Windows Vista has many layers of defense, including the firewall, running as a standard user, Internet Explorer Protected Mode, /NX support, and ASLR, which help prevent arbitrary code from running with administrative privileges," the Microsoft representative noted.

After the presentation on bypassing the driver shield, Rutkowska presented a way to create the stealthy malicious software she code-named Blue Pill. The technique uses Pacifica, a Secure Virtual Machine, from chipmaker Advanced Micro Devices, to go undetected.

Blue Pill could serve as a backdoor for attackers, Rutkowska said. While it was developed on Vista and AMD's technology, it should also work on other operating systems and hardware platforms. "Some people suggested that my work is sponsored by Intel, as I focused on AMD virtualization technology only," she said, adding that is untrue.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote

Sponsored Links
Reply

Bookmarks

Tags
hacked, vista
Search Cloud
2009 audi s3 2009 e class 2009 e-class 2009 ml350 2010 audi a6 2010 cayenne 2010 clk 2010 porsche cayenne 2010 range rover 2010 range rover sport 2010 rolls royce 2010 touareg a5 cab audi a4 b8 audi a5 cab audi a5 sportback audi a6 2010 audi a6 c7 audi a8 d4 audi a9 audi c7 audi d4 audi r15 audi rs3 audi rs4 b8 audi s3 2009 audi s3 sportback audi s4 b8 b8 a4 b8 rs4 bentley suv bmw 1m bmw e89 bmw e90 facelift bmw f01 bmw f10 bmw m3 touring bmw m7 bmw z4 e89 brunei cars bugatti owners bugatti veyron convertible c300 4matic carrera gt1 carzone cayenne 2010 citroen c6 musketier clk 2010 colani ferrari e class 2009 e-class 2009 e89 z4 e90 lci ferrari colours fiat canada german car german car zone german cars germancar germancarzone germancarzone.com gl63 gl63 amg jetta facelift koenigsegg configurator m3 csl for sale m3 touring m3 vs 335i maybach coupe ml facelift ml350 2009 nissan skyline nude babes nurburgring webcam opel astra 2009 pagani zonda price porsche cayenne 2010 porsche gt1 range rover 2010 rs4 b8 scirocco r36 seat leon facelift sharpie lamborghini sultan brunei cars sultan of brunei sultan of brunei car sultan of brunei car collection sultan of brunei car list sultan of brunei cars sultan of brunei garage sultan of brunei's cars tiguan diesel touareg 2010 w212 weismann car weismann cars weismann roadster white r8 www.germancarzone.com z4 e89

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista Bèta 2 RikfromBelgium Computers 9 06-13-2006 10:55 PM