Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

MICROSOFT

Microsoft Bulletproofed Vista Against the Blue Pill Rootkit

- Or didn't it?

By: Marius Oiaga, Technology News Editor

Back in August, at the Black Hat conference in Las Vegas, security expert Joanna Rutkowska from the Singapore-based firm COSEINC, had bypassed Windows Vista 64-bit edition's Patch Guard and performed a malware code injection. That malware code was none other than the Blue Pill rootkit.

Well, Rutkowska herself revealed that Windows Vista is no longer vulnerable. "I had a chance to download Vista RC2 x64 and test it against the pagefile attack... It quickly turned out that our exploit doesn’t
work anymore! The reason: Vista RC2 now blocks write-access to raw disk sectors for user mode applications, even if they are executed with elevated administrative rights," stated Rutkowska. The image on the left clearly illustrates Rutkowska's statement.

Rutkowska has presented three potential mitigations for the pagefile attack:
1. Block raw disk access from usermode.
2. Encrypt pagefile (alternatively, use hashing to ensure the integrity of paged out pages, as it was suggested by Elad Efrat from NetBSD).
3. Disable kernel mode paging (sacrificing probably around 80MB of memory in the worst case).

According to Rutkowska, disallowing raw disk access was not the most comprehensive approach as it would generate incompatibility issues without actually resolving the problem. Why? Because legitimate kernel drivers designed to deliver compatibility with Vista to, let's say, a disk editor, could be geared toward malicious purposes involving accessing raw disk sectors via a pagefile attack.

"The point here is, again, there is no bug in the driver, so there is no reason for revoking a signature of the driver. Even if we discovered that such driver is actually used by some people to conduct the attack! But it seems that MS actually decided to ignore those suggestions and implemented the easiest solution, ignoring the fact that it really doesn’t solve the problem" concluded Rutkowska.

MORE RELATED ARTICLES: Microsoft Details Kernel Patch Protection in Vista Microsoft Opens Vista’s Core Symantec Attacks Windows Vista's Security Features Vista PatchGuard Hacked Symantec Advises Microsoft on PatchGuard McAfee Aims for Microsoft's Jugular Vista's Patch Guard is Killing Next Generation Behavior-Blocking Technologies and Future Security Models Symantec Predicts Windows Vista to Be a Security Liability Microsoft Gets Additional Support for the Security Features Introduced in Vista Microsoft Increasing Security Risk with Vista
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:

20th October 2006, 13:10 GMT | Copyright (c) 2006 Softpedia | Contact:
Read by 2,069 user(s) | Rating: | 9 vote(s) so far | Cast your vote:
Microsoft Bulletproofed Vista Against the Blue Pill Rootkit - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Microsoft Bulletproofed Vista Against the Blue Pill Rootkit

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive