Researchers at Black Hat Reveal Major Vista Security Issue
Researchers at Black Hat Reveal Major Vista Security Issue
by , 2:00 PM EDT, August 8th, 2008
On day two of the Black Hat security conference, Mark Dowd with IBM and Alexander Sotirov with VMware presented a paper on a technique to completely bypass the memory protection features of Microsoft Vista along with recommendations to Microsoft.
In their talk, entitled, "How to Impress Girls with Browser Memory Protection Bypasses," the researchers showed how take advantage of the way IE and other browsers handle active scripting in the OS.
The description of the presentation from the Black Hat conference said:"Over the past several years, Microsoft has implemented a number of memory protection mechanisms with the goal of preventing the reliable exploitation of common software vulnerabilities on the Windows platform. Protection mechanisms such as GS, SafeSEH, DEP and ASLR complicate the exploitation of many memory corruption vulnerabilities and at first sight present an insurmountable obstacle for exploit developers.
"This talk aims to present exploitation methodologies against this increasingly complex target. We will demonstrate how the inherent design limitations of the protection mechanisms in Windows Vista make them ineffective for preventing the exploitation of memory corruption vulnerabilities in browsers and other client applications.
"Each of the aforementioned protections will be briefly introduced and its design limitations will be discussed. We will present a variety of techniques that can be used to bypass the protections and achieve reliable remote code execution in many different circumstances. Finally, we will discuss what Microsoft can do to increase the effectiveness of the memory protections at the expense of annoying Vista users even more."
Vista, as well as Mac OS X and Linux, uses a technique called ASLR to randomly change the locations of certain addressable memory locations so that malware cannot insert executable code. It's not a substitute for secure code, but can reduce vulnerability. Mr. Dowd's presentation focused on how to get around ASLR and other techniques like Data Execution Prevention (DEP).
Back in June, Mr. Dowd predicted that his coming demonstration would obliterate Vista security improvements.
"We're going to show a couple of ways you can tip the odds in your favour so vulnerabilities can be easily exploited by techniques that bypass these protection mechanisms," he said. "Some completely obliterate the protections."
According to neowin.net, Dino Dai Zovi, a popular security researcher said, "the genius of this is that it's completely reusable. They have attacks that let them load chosen content to a chosen location with chosen permissions. That's completely game over."
Microsoft is aware of the issue, and the verdicts are just starting to come in how how serious this breach is and what can be done to prevent it. The good news is that as these exploits are discovered and analyzed by the good guys at conferences like Black Hat, the OS vendors can work to remain one step ahead of the bad guys.
Observer Comments
Ultimately the cause of such errors such as buffer overruns, which is one of the oldest hacking techniques, is not the OS. Vista simply can not stop flaws created by 3rd party apps, it can however slow them down. If you pay attention to recommended settings, and the admin elevation pop ups, and do as Microsoft recommends (do not log on as admin, elevate as needed,) then most problems are avoided. Also, this bug applies to XP as well. Vista's security is not broken, just not as rock solid as we initially thought.
Comments are currently closed. Please email the author instead.
Recent Headlines - Updated February 9th
- Tue, 2:27 PM
- Deal Brothers - Refurbished 13” MacBook 2.13GHz Intel Core 2 Duo: $749
- 1:31 PM
- Jeff Gamet's Blog - Macworld Expo: It’s Our Show, Not Apple’s
- 10:38 AM
- Quick Look Review - Texas Tea for the iPhone and iPod touch
- 10:25 AM
- News - Apple Rolls Out Aperture 3 Video Tutorials
- 10:00 AM
- Hot Forum Topic - Backing Up Your iPhoto Library
- 9:35 AM
- Product News - Notebook, iThoughts Add TextExpander touch Support
- 9:00 AM
- Hidden Dimensions - The Killer Surprises Waiting for Steve Ballmer
- 8:50 AM
- Product News - Aperture 3 Adds Faces Support, More [Updated]
- 8:30 AM
- TMO Quick Tip - Fixing iPhone and MobileMe Sync Headaches
- 8:12 AM
- News - Apple Store Offline, Rumors Point to New Laptops
- 8:00 AM
- TMO Appearances - TMO’s Bryan Chaffin and the Atomic Love Bombs Perform During Macworld Expo
- Mon, 5:37 PM
- News - Juniper Readies Software to Improve Cell Carrier Networks
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
RamJet Memory: Mac Pro 8GB Kit $275.99, Mac Pro 4GB Kits $145.99! Sale on MacBook and MacBook Pro 8GB kits $459.99! MacBook, MacBook Pro, iMac Mac mini 4GB Kits for $113.99! 1TB SATA Hard Drives for $109.99! Click here- If you own a car, you need CarMD! Catch problems, estimate repairs and more. Now for Mac. $98.99 at www.CarMD.com Save $10 with code TMO1.
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.


