Jump to content
w¡n9Nµ7 §£@¥€r

Vista's Security Rendered Completely Useless by New Exploit

 Share

7 posts in this topic

Recommended Posts

Filed: Timeline

Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. have discovered a technique that can be used to bypass all memory protection safeguards that Microsoft built into Windows Vista ... The researchers were able to load whatever content they wanted into any location they wished on a user's machine using a variety of objects, such as Java, ActiveX and even .NET objects. This feat was achieved by taking advantage of the way that Internet Explorer (and other browsers) handle active scripting in the Operating System.

While this may seem like any standard security hole, other researchers say that the work is a major breakthrough and there is very little that Microsoft can do to fix the problems. These attacks work differently than other security exploits, as they aren't based on any new Windows vulnerabilities, but instead take advantage of the way Microsoft chose to guard Vista's fundamental architecture. According to Dino Dai Zovi, a popular security researcher, "the genius of this is that it's completely reusable. They have attacks that let them load chosen content to a chosen location with chosen permissions. That's completely game over."

...

While Microsoft hasn't officially responded to the findings, Mike Reavey, group manager of the Microsoft Security Response Center, said the company has been aware of the research and is very interested to see it once it has been made public. It currently isn't known whether these exploits can be used against older Microsoft Operating Systems, such as Windows XP and Windows Server 2003, but since these techniques do not rely on any one specific vulnerability, Zovi believes that we may suddenly see many similar techniques applied to other platforms or environments.

http://www.neowin.net/news/main/08/08/08/v...-by-new-exploit

Man is made by his belief. As he believes, so he is.

Link to comment
Share on other sites

Back in the day, my parents waited in long car lines to deposit checks and withdrawl cash with actual tellers handling transactions. We might return to this one day if things persist.

Ken y Leidys’ Timeline

May 1, 2009 - I-129 F (NOA-1)

Aug 4, 2009 - I-129 F (NOA-2)

Oct 7, 2009 - Bogota Interview

Oct 16, 2009 - Diomesa package arrived in downtown Barranquilla

Oct 20, 2009 - Leidys took bus to Diomesa Office to pick up Visa/Passport package because ("We don't deliver to your Barrio").

Nov 22, 2009 - POE (30 min.) Los Angeles, Intl.

Dec 27, 2009 - Wedding

March 8, 2010 - AOS NOA

April 8, 2010 - AOS BIO (in Riverside, CA)

May 11, 2010 - AOS AP

May 24, 2010 - AOS Interview

May 27, 2010 - AOS EAD May 27, 2010

Jun 18, 2010 - Green Card Received!

Apr 07, 2012 - ROC Filed

Oct 11, 2012 - ROC RFE

Jan 08, 2013 - CONDITIONS REMOVED!!!

VicFrndz.jpgBAQ+Taxi.jpgclubberz.jpgCumbiaz.jpg

Link to comment
Share on other sites

Filed: Citizen (apr) Country: Brazil
Timeline

sales of vista should drop even more now. and i think you're right, ken.

* ~ * Charles * ~ *
 

I carry a gun because a cop is too heavy.

 

USE THE REPORT BUTTON INSTEAD OF MESSAGING A MODERATOR!

Link to comment
Share on other sites

Filed: Citizen (pnd) Country: Hong Kong
Timeline

So, can we have XP back, since Vista isn't any more secure than XP anyway?

Scott - So. California, Lai - Hong Kong

3dflagsdotcom_usa_2fagm.gif3dflagsdotcom_chchk_2fagm.gif

Our timeline:

http://www.visajourney.com/forums/index.php?showuser=1032

Our Photos

http://www.amazon.ofoto.com/I.jsp?c=7mj8fg...=0&y=x7fhak

http://www.amazon.ofoto.com/BrowsePhotos.j...z8zadq&Ux=1

Optimist: "The glass is half full."

Pessimist: "The glass is half empty."

Scott: "I didn't order this!!!"

"Where you go I will go, and where you stay I will stay. Your people will be my people and your God my God." - Ruth 1:16

"Losing faith in Humanity, one person at a time."

"Do not put your trust in princes, in mortal men, who cannot save." - Ps 146:3

cool.gif

IMG_6283c.jpg

Vicky >^..^< She came, she loved, and was loved. 1989-07/07/2007

Link to comment
Share on other sites

Filed: Citizen (pnd) Country: Cambodia
Timeline

Vista can support more than 4 Gb of memory versus XP. With more applications taking advatange of more features such a photoshop (higher megapixels = larger memory needed), video application, etc...It's essential to adapt an OS that supports more than 4GB of memory.

The technicality is this, 2^32 memory locations equals approx. 4 gb. The 32 is the amount of bits the OS supports. Vista can support 64 bits, 2^64 memory locations is approx. 18,000 PB (not peanut butter) which is about 18 million Gb.

There will always be holes within an OS. The complexity of taking advantage of the hole will also become very complex.

Hey, there are still people who wants to get back into DOS. ROFL. I'm not surprised.

Edited by consolemaster

mooninitessomeonesetusupp6.jpg

Link to comment
Share on other sites

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
- Back to Top -

Important Disclaimer: Please read carefully the Visajourney.com Terms of Service. If you do not agree to the Terms of Service you should not access or view any page (including this page) on VisaJourney.com. Answers and comments provided on Visajourney.com Forums are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Visajourney.com does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. VisaJourney.com does not condone immigration fraud in any way, shape or manner. VisaJourney.com recommends that if any member or user knows directly of someone involved in fraudulent or illegal activity, that they report such activity directly to the Department of Homeland Security, Immigration and Customs Enforcement. You can contact ICE via email at Immigration.Reply@dhs.gov or you can telephone ICE at 1-866-347-2423. All reported threads/posts containing reference to immigration fraud or illegal activities will be removed from this board. If you feel that you have found inappropriate content, please let us know by contacting us here with a url link to that content. Thank you.
×
×
  • Create New...