Most Popular Stories
- 3 ways for CIOs to become business leaders
- Chrome 17's new features enhance speed, security
- FBI insists cloud providers meet strict security requirements
- Spotlight: Intel launches 520 Series solid-state drive
- Bug in Trendnet webcams exposes them to public viewing
- Multiple monitors makes some multitasking faster, easier
Events
- COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Case Study: ABBYY FineReader® Engine Drives Demand for ECM Software Leader
- Reporting 2.0 – The next evolutionary step in web based business reporting
- CSO White Paper - Desktop Virtualization: Empowering Information Security
- Five Tips to Get IT Auditors Off Your Back
- 8 Critical Requirements for Secure, Mobile File Transfer and Collaboration
Microsoft blocks Vista hack, opens new can of worms
At the Black Hat convention back in August, Polish researcher Joanna Rutkowska demonstrated a Vista hack that bypassed security in the 64-bit version of Vista to run unsigned driver code, which could be used to install malicious drivers on a user's hard drive. So here's the good news: Microsoft has since made changes to Vista's code that prevent such an attack. The bad news? Apparently, the company addressed the vulnerability by blocking write-access to raw disk sectors for applications that run in user-mode, including those that are executed with administrative rights. While this solution does prevent the specific exploit demonstrated at Black Hat, it introduces a new set of problems: blocking access to raw disk sectors could cause compatibility problems for programs like disk editors and disk recovery tools. What's more, instead of using an unsigned driver, a hacker could simply hijack a legitimate driver in order to execute the same attack. Rutkowska apparently addressed these concerns during her talk back in August, "But it seems that MS actually decided to ignore those suggestions and implemented the easiest solution, ignoring the fact that it really doesn't solve the problem," she recently wrote on her blog. Looks like security vendors won't be the only ones up in arms over the 64-bit version of Vista, eh?
For more on the hack:
- check out this post on Joanna Rutkowska's blog, Invisible Things
- or read the write-up at ZDnet
Related Stories
- Mozilla: We'll patch flaws in 10 [expletive] days
- Third Symantec report finds Vista bugs
- Unpatched flaw revealed in Cisco firewall
- Intel offers security fixes for Centrino wireless chips
- Researchers to break NAC defense at Black Hat
- User names and passwords of 1.3 million stolen in weekend Gawker Media hack
- McAfee: Malware at all-time high
- Java exploits at all time high, patch if you have not done so
- GoDaddy hosted sites hit again by PHP attack
- Use passwords of at least 12 characters to protect against hacking
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




