NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Hacking into Vista

At the Black Hat convention in Las Vegas

By Marius Oiaga, Technology News Editor

26th of July 2006, 13:03 GMT

Adjust text size:


In the wake of Symantec's second report related to Windows Vista vulnerabilities, at the Black Hat conference in Las Vegas a security researcher will make a public demonstration hacking into Vista kernel.
Joanna Rutkowska, senior security researcher for COSEINC from Singapore will present proof-of-concept that inserts malware past the operating system's security. This is possible by bypassing security with the aid of digitally signed code that loads directly into the Vista kernel.

In her demonstration, Rutkowska will disable Vista's signature-check tool, opening the way for malware execution in kernel mode. In this manner, sniffers, keyloggers and backdoor Trojans could find their way into Vista's basic services, and from the OS's fundamentals allow for remote control of the compromised machine.

"For the attack to succeed, one needs to find a reliable way to force interesting kernel code to be paged out, then find that code inside a page file and modify it. And finally, the kernel needs to load that code (now modified) again into physical memory and execute it," explained Rutkowska. "The proof-of-concept code I implemented solves all those challenges allowing for very reliable exploitation." Rutkowska blames the vulnerability on Microsoft's operating structure, stating that the fact that mode applications can access raw disk sectors is in fact a design problem.

As a conclusion, the researcher stated that she is impressed with the overall performance of Windows Vista, and how the operating system balances security and functionality.
Read by 4,427 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 11 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Unveils Plan for Windows Vista Upgrade

Ballmer Is 100% Behind Vista

Microsoft Kills Vista Beta 2

New Windows Vista Beta 2 Build Release

Free Vista Virtual PC from Microsoft

New Vista Beta Coming this Week

Microsoft Makes Vista Presentation on MacBook Pro

Microsoft Stands to Lose $400.000.000 on Another Vista Delay

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM