Linked by Amjith Ramanujam on Fri 8th Aug 2008 13:14 UTC
Windows This week at the Black Hat Security Conference two security researchers will discuss their findings which could completely bring Windows Vista to its knees. According to Dino Dai Zovi, a popular security researcher, "the genius of this is that it's completely reusable. They have attacks that let them load chosen content to a chosen location with chosen permissions. That's completely game over."
Thread beginning with comment 326203
To read all comments associated with this story, please click here.
this news is pure .FUD.
by casuto on Fri 8th Aug 2008 13:40 UTC
casuto
Member since:
2007-02-27

this news is pure .FUD.

Reply Bookmark Score: -13

RE: this news is pure .FUD.
by liamdawe on Fri 8th Aug 2008 13:52 in reply to "this news is pure .FUD."
liamdawe Member since:
2006-07-04

Why exactly is it FUD, what makes it FUD. Seems perfectly valid to me if you actually read it all the way through and not skim the article.

Reply Parent Bookmark Score: 8

FellowConspirator Member since:
2007-12-13

How so. I understand exactly what they're talking about, and while it's not presented very well, it's basically correct. It basically just makes an end-run around ASLR and uses the kernel to overwrite blocks of memory (including the kernel itself) and execute whatever it is. The exploit is really one of the fundamental model of the kernel's operation rather than any particular application or system.

I suppose it could be FUD if you thought that the exploit wasn't an intentional design decision. I'm not sure it is.

Either way, I suppose it's not so important as Vista's probably not going to gain sufficient traction for it to matter. They either fix it in Win7, or it will be irrelevant post-Win7 (which I'm guessing is the end of the line for NT-based kernels, if not the "Windows" brand).

Reply Parent Bookmark Score: 6

Neowin's Plagiarism
by linumax on Fri 8th Aug 2008 14:41 in reply to "this news is pure .FUD."
linumax Member since:
2007-02-07

Sorry to steal the thread, but would be nice if OSNews links the original story from Techtarget/SearchSecurity as it seems like Neowin stole the story without attribution.

Neowin also removed the comments on the story which gave them away, as if the Internet could be fooled that easily!

Original:

http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gc...

Edit:

Link to PDF with more details:
http://taossa.com/archive/bh08sotirovdowd.pdf
( taken this from /. )

Edited 2008-08-08 14:47 UTC

Reply Parent Bookmark Score: 17

RE: this news is pure .FUD.
by StephenBeDoper on Fri 8th Aug 2008 17:48 in reply to "this news is pure .FUD."
StephenBeDoper Member since:
2005-07-06

Not so much FUD as a demonstration of Fudd's First Law of Opposition ("If you push something hard enough, it will fall over").

Reply Parent Bookmark Score: 4