Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

ASLR FAIL?

txttxtBetter Heap Management? Is that so?

You know: I personally like the Vista GUI because it's a little darker and more elegant than XP. I'm doing some Reversing with IDA, Ollydbg, SoftICE - and a little eye-candy is never wrong. So I thought Vista is good for you. New user separation like sudo, 64 Bit with device drivers on a MacBook (needs some tricks). And you can debloat it. Working without THE professional (proprietary) software sometimes is impossible, while earning money with IT.

Actually, I read that most developers ignore Vista's new security features - because they're too complex. I'm currently doing some research in Visual C# - just because I'm interested - and I found out that it's definitely not too complex. If there's a high level API to call out of a C# program to use ASLR functions to allocate securely - that seems fine. or seemed.

Now Blackhat Con brought something HUGE. Sometimes people say Schneier is overrated, but even he declares this being "huge".


In a presentation at the Black Hat briefings, Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. will discuss the new methods they've found to get around Vista protections such as Address Space Layout Randomization(ASLR), Data Execution Prevention (DEP) and others by using Java, ActiveX controls and .NET objects to load arbitrary content into Web browsers.


If that's deep and true - MS invested 100 Million bucks in nothing. If that's true, Vista is a complete failure, technically, and for the whole Microsoft community.

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.