Linked by Thom Holwerda on Fri 5th Jan 2007 20:11 UTC, submitted by sogabe
Permalink for comment 199004
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/19/13 23:15 UTC
Linked by Thom Holwerda on 05/19/13 23:11 UTC, submitted by Drumhellar
Linked by Thom Holwerda on 05/18/13 21:06 UTC
Linked by Thom Holwerda on 05/18/13 7:37 UTC
Linked by fran on 05/18/13 1:38 UTC
Linked by Thom Holwerda on 05/17/13 23:35 UTC, submitted by kragil
Linked by MOS6510 on 05/17/13 22:22 UTC
Linked by Thom Holwerda on 05/17/13 22:15 UTC, submitted by Tom
Linked by Thom Holwerda on 05/16/13 21:41 UTC
Linked by Thom Holwerda on 05/16/13 17:04 UTC
More News »
Sponsored Links



Member since:
2005-09-10
the statement was -"it is not possible to examine a system from the outside without notifying the user due to the architecture of this software." all the examples from MauriceK where of abuses from the inside, in other words, it requires user action, like executing a malicious program. if he had shown examples that remotely connected and executed code on a zeta machine then it would have made some sense in this context.
... until you ran an application that has remote code execution vulnerability. Or what about portscans - you can use use nmap to scan a Zeta machine, which surely qualifies as an examination from the outside
)) But jokes aside, what Maurice shows is that due to the "architecture of this software," it is very very easy to hide malicious software on the system without the user having any chance to notice them. Of course this depends on user-interaction, and once the code is on your puter, it qualifies as an "inside" attack vector, but still, the original statement is false (as in meaningless), and its only purpose is to lull users into a false sense of security.
The vast majority of security issues with WinXP is due to attacks from the inside, malicious code that found its way to your hard-drive. The statement Maurice set out to debunk is completely bogus. You can make the same claim of any OS, including win98