New inbreak the method is accessibility Vista system is internal
August 10, 2008
[message of motivation of ENet Silicon Valley] report according to foreign media, hold in this week ” black hat ” on congress, two safe researcher state they will discuss the newest discovery that can open Windows Vista system completely for the hacker achievement.
The safe researcher Alexander Sotirov of the Mark Dowd of Internet safety researcher that comes from IBM company and VMware company claims jointly, they discovered can bypass the measure of all storage protection on Windows Vista system, and enter Windows Vista system.
Two researcher express, their method can bypass on Vista system ” layout of address space randomization ” (ASLR) and ” data carries out protection ” (DEP) and prevent to carry ill will of to load of standard webpage browser with etc the forthright safeguard of software.
Dowd and Sotrirov can use various script languages, include ActiveX, Java and.NET inside, in do not agree with a circumstance to fall to enter user system at will via the user.
Look from apparent, the discovery of two afore-mentioned researcher is similar to run-of-mill fundamental safety problem. But other researcher expresses clearly, their discovery is a inside safe domain major breakthrough, it is very intractable to rise at be being handled for Microsoft, microsoft delicacy has method to come repair these problems. The safe foundation framework that designed Microsoft Vista system because of the method that they use.
Researcher expresses, the possibility on the other operating system that they believe to be in Microsoft is put possibly also in similar technical application, include previously the Windows system of version.
Microsoft is done not have to this make formal response. Microsoft safety answers central controller Mike Reavey to express, they already learned this message, once research detail is made public, microsoft will give attention.
Author: Green plum
Tags: accessibility, inbreak, method, new, Vista


