Most Popular Stories
- Chrome 17's new features enhance speed, security
- Apple's iPad 3 will be unveiled first week of March, says report
- Microsoft: How Windows 8 on ARM will be different
- Bug in Trendnet webcams exposes them to public viewing
- Microsoft's Patch Tuesday for February has 9 security bulletins
- Nearly half of U.S. businesses to have mobile apps this year
Events
- The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - CIO Healthcare Summit
March 11-14 — Scottsdale, AZ
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Reporting 2.0 – The next evolutionary step in web based business reporting
- Ensuring Cultural Adoption
- Penetration Testing with Metasploit Framework
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- Making Change Stick
Released: Exploit code to bypass DEP security in Windows
Google security software engineer Berend-Jan Wever has published proof-of-concept code on how to bypass Microsoft's data execution prevention technology, or DEP. First introduced in Windows XP Service Pack 2, DEP prevents malicious code from executing in memory spaces not meant for code execution. This helps the operating system defend against various types of attacks, including those based on buffer overflows.
Wever worked for Microsoft as a security software engineer from 2006 to 2008. In his personal blog, he says that the decision to publish the exploit is to demonstrate that the combined use of ASLR and DEP are not a mitigation to "put a lot of faith in." ASLR stands for address space layout randomization, a technique in which the position of key memory areas are randomly shuffled around to thwart hackers from predicting whether their exploit code will actually run.
Where ASLR is concerned, Wever wrote that on the x86 platform at least, "32-bits does not provide sufficient address space to randomize memory to the point where guessing addresses becomes impractical, considering heap spraying can allow an attacker to allocate memory across a considerable chunk of the address space and in a highly predictable location."
Heap spraying was a technique Wever popularized in 2005 to make exploits against browsers more efficient. Senior threat researcher at Trend Micro David Sancho noted that the demonstration "is pretty significant." According to Sancho, "This can be used to further enhance exploits, and I expect that we'll start seeing it being used within exploits fairly soon."
For more on this story:
- check out this article at Computerworld
- check out Wever's personal blog
Related Articles:
Moving to exploit SSD in the enterprise
Adobe to push out new Acrobat security patches today
Serious flaw discovered in Microsoft IIS
Hackers fix Microsoft security patch BSOD problem
Related Stories
- Tech giants team up to combat phishing with new email specification
- Bing draws closer to Yahoo in U.S. Internet search engine market
- Internet Explorer to get silent updates
- Google Chrome takes No. 2 spot in desktop browser war
- Google, Mozilla, Microsoft blacklist DigiNotar, but Apple remains silent
- Box.net unveils integration with Google Docs
- Insider on why Microsoft bought Skype
- Microsoft decries hidden 'Google Tax'
- Trend Micro bumps a Zeus botnet server off the Net
- Web authentication company fingers Iran for sophisticated hack
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




