NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Security

Security


Apple Adopts Windows Vista Security Mitigations

For its own solutions

By Marius Oiaga, Technology News Editor

8th of April 2008, 09:57 GMT

Adjust text size:



Enlarge picture
In a new move designed to add anti-hacking features to its solutions, Apple is contradicting the general perspective that its products offer security by default, in contrast with Microsoft's software. The Cupertino-based hardware company is working to bulletproof its own software against hacking attempts and,
in this context, managed to embrace security mitigations introduced as defaults into Windows Vista. The targeted product for the new exploit prevention mechanisms is none other than the QuickTime media player.

Microsoft solutions, from the Windows operating systems to the Internet Explorer browsers, are generally perceived as inferior in terms of security to what Apple has to offer. And the Cupertino-based company has fueled this perspective through marketing. Still, Apple failed to hesitate in embracing security mitigations specific of the Windows Vista platform for QuickTime 7.4.5. According to EWeek, citing sources familiar with the situation, Apple has integrated an exploit prevention mechanism (XPMs) into QuickTime 7.4.5 for both Mac OS X and Windows. This was done via a recent update for the media player which also contributed to patching approximately a dozen of security vulnerabilities in the product.

As far as QuickTime for Vista is concerned, the media player now comes with Address space layout randomization (ASLR). "ASLR moves images into random locations when a system boots and thus makes it harder for shell code to operate successfully. For a component to support ASLR, all components that it loads must also support ASLR. For example, if A.EXE consumes B.DLL and C.DLL, all three must support ASLR. By default, Windows Vista will randomize system DLLs and EXEs, but DLLs and EXEs created by ISVs must opt in to support ASLR," reads Microsoft's official description of the security mitigation.

In addition to ASLR, QuickTime is also getting a feature designed to check the status of the stack buffer. Vista itself has a few extra lines of defense in comparison to its predecessor and in addition to ASLR, including stack buffer overrun detection, SafeSEH exception handling protection, no eXecute (NX) / Data Execution Prevention (DEP) / eXecute Disable (XD), heap randomization, stack randomization and heap corruption detection.

TAGS:

Windows Vista | Apple | QuickTime | ASLR
Read by 1,175 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.8/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


SP1 Drops as Vista Hugs from 13.24% to 14.02% of the Market

Apple Mocks Vista (SP1) and Praises Hack Victim No. 1 Leopard

What's New in Firefox 3.0 Beta 5

Microsoft Finds Irony in Mac OS X Getting Hacked Before Vista SP1

If You Think Mac OS X Is More Secure than Windows, Think Again

Apple Puts an End to Illegal Safari Installations on Windows PCs

Vista SP1, XP SP3 and Windows 7 Need to Be on the Lookout for Leopard(s)

Mozilla Welcomes Competition but Says Apple Uses Malware Distribution Practices

Apple Pushes Safari Down the Throat of Windows Users, Like It or Not

Between XP SP2 and Vista SP1, Apple Brought a World of Pain on Microsoft

Safari 3.1 Beats Firefox 3 and IE8 to the Market

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM