|
|
Microsoft Blocks Windows Vista Rootkit Exploit - TechAmok
Microsoft Blocks Windows Vista Rootkit Exploit - [security] 06:41 PM EDT - Oct,20 2006 - post a comment Microsoft
has blocked the attack vector used to slip unsigned drivers past new
security policies being implemented in Windows Vista, according to Joanna
Rutkowska, the stealth malware researcher who created the exploit. Rutkowska,
who demonstrated the exploit at the Black Hat conference in August, said she
tested the attack against Windows Vista RC2 x64 and found that the exploit
doesn't work anymore. "The reason: Vista RC2 now blocks write-access to
raw disk sectors for user mode applications, even if they are executed with
elevated administrative rights," Rutkowska wrote on her Invisible Things blog.
Rutkowska, a Windows Internals expert at Singapore-based IT security firm
COSEINC, however warned that the way the exploit is being blocked could be
problematic and cause application compatibility issues.
Imagine a company wanting to release e.g. a disk editor. Now, with the blocked write access to raw disk sectors from usermode, the company would have to provide their own custom, but 100% legal, kernel driver for allowing their, again 100% legal, application (disk editor), to access those disk sectors, right? Of course, the disk editor's auxiliary driver would have to be signed - after all it's a legal driver, designed for legal purposes and ideally having neither implementation nor design bugs! But, on the other hand, there is nothing which could stop an attacker from "borrowing" such a signed driver and using it to perform the pagefile attack. The point here is, again, there is no bug in the driver, so there is no reason for revoking a signature of the driver. Even if we discovered that such driver is actually used by some people to conduct the attack! But it seems that MS actually decided to ignore those suggestions and implemented the easiest solution, ignoring the fact that it really doesn't solve the problem…
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
|
Feb,25 2026 Samsung Previews New AI Features Ahead of Flagship Phone Launch Feb,25 2026 China's DeepSeek Bars Nvidia and AMD from New AI Model, Boosts Feb,25 2026 Avast Impersonation Scam: Fake Site Tricks Users into Handing Over Feb,25 2026 Microsoft Pulls the Plug: Windows Server 2016 and 2016-Era Windows Feb,25 2026 I Scrapped 13 MACHINES to Prove a Point: STOP BUYING These Brands! Feb,25 2026 How Stealthy was the 7zip Malware and how to spot it? Feb,25 2026 Microsoft Drops Fresh Non-Security Boost for Windows 11 24H2 and Feb,24 2026 Game-Changer: ASML's 1kW EUV Upgrade Promises 50% Chip Production Feb,24 2026 This Outstanding Cooling Technology Might Have No Future Feb,24 2026 AMD Strix Halo 395 vs Intel Panther Lake - Real Benchmarks Feb,24 2026 Anthropic published a blog post saying Claude can modernize COBOL Feb,24 2026 WhatsApp Goes Beyond 2FA: Extra Password Layer Makes Accounts Nearly Feb,24 2026 Google Chrome Gets February 23 Security Boost with 3 High Fixes Feb,23 2026 Stargate Stalls: OpenAI's $500B Dream Hits Roadblocks as $14B 2026 Feb,23 2026 Google Crushes Cyber Threats: Blocks 1.75 Million Bad Apps and Bans Feb,22 2026 Bitcoin Miner Bitdeer Sells Everything: Treasury Hits Zero in AI Feb,22 2026 HW News - More Valve RAM Shortages, Tariffs Ruling, AI Causes PS6 Feb,22 2026 Microsoft's Deep Integration of Copilot in Windows 11 Raises Feb,22 2026 Elon Musk Confirms X Money Now Live in Internal Beta for Employees, Feb,22 2026 Scream (1996) Flashback Review Feb,22 2026 PayPal Confirms Major Breach: SSNs, Emails, and More Exposed from Feb,22 2026 Does Freezing Help Delidding? 9850X3D Delid & Overclocking Test Feb,22 2026 Microsoft is phasing out the custom primary password feature in its Feb,21 2026 Everyone is Buying the Wrong Dash Cam! (2026) Feb,20 2026 Big Brother on Discord: Leaked Code Shows Age Verification Runs You Feb,19 2026 OpenClaw’s Top Skill is a Malware that Stole SSH Keys and Opened Feb,19 2026 Google Adds Satellite SOS to its Affordable Pixel Phone Feb,19 2026 Phison CEO Warns: AI-Driven NAND and DRAM Shortage Could Bankrupt Feb,19 2026 NVIDIA CEO hypes up GTC 2026, promises to unveil a chip that will Feb,19 2026 Microsoft is uploading your confidential emails to Copilot for Feb,18 2026 Anthropic Releases Claude Sonnet 4.6 with Improved Coding, Computer Feb,17 2026 Apple Eyeing A Partnership With Chinese Memory Makers YMTC And CXMT Feb,17 2026 This $60,000 TV was IRRESISTIBLE Feb,17 2026 Keenadu Android Backdoor Infects Firmware, Spreads via Google Play Feb,17 2026 Discord's ID Check Nightmare Sparks Massive Exodus to TeamSpeak Feb,17 2026 Amazing Robot Performance at the 2026 Spring Festival Gala Feb,16 2026 Apple brings video podcasts and other improvements in iOS 26.4 beta Feb,16 2026 Dutch Defence Secretary Boldly Claims F-35 Software Could Be Feb,16 2026 Samsung shows off Galaxy S26 Ultra privacy display Feb,16 2026 60 Million Passwords Exposed? ETH Zurich Shatters 'Unbreakable'
>> News Archive <<
| |
|