Next-Generation Win32 exploits: fundamental API flaws This paper presents a new generation of attacks against Microsoft Windows, and possibly other message-based windowing systems. The flaws presented in this paper are, at the time of writing, unfixable. The only reliable solution to these attacks requires functionality that is not present in Windows, as well as efforts on the part of every single Windows software vendor. Microsoft has known about these flaws for some time; when I alerted them to this attack, their response was that they do not class it as a flaw - the email can be found here. This research was sparked by comments made by Microsoft VP Jim Allchin who stated, under oath, that there were flaws in Windows so great that they would threaten national security if the Windows source code were to be disclosed. He mentioned Message Queueing, and immediately regretted it. However, given the quantity of research currently taking place around the world after Mr Allchin's comments, it is about time the white hat community saw what is actually possible.
Wednesday, August 07, 2002
Subscribe to:
Post Comments (Atom)
Edward A. Villarreal. Powered by Blogger.
Labels
- 700MHz Auction (4)
- 9/11 (6)
- Abramoff (9)
- aging (1)
- AIG (1)
- Aircraft (6)
- Alec Baldwin (1)
- AMD (2)
- Amish (1)
- Apple (1)
- Archaeology (3)
- Art (1)
- Astronomy (29)
- Autism (1)
- Automobile (1)
- Baby pictures (1)
- backup (1)
- Bad Laws (12)
- bamboo (1)
- Barcelona (1)
- batteries (3)
- Belinda Carlisle (14)
- Bicycle (13)
- Bill Clinton (1)
- Billie Davis (1)
- Billie Piper (1)
- Biology (38)
- Blogger (3)
- Blondie (2)
- blood libel (1)
- Boats (1)
- books (5)
- Boston (1)
- bug (6)
- Bush (61)
- Cancer (4)
- Catalog (1)
- cats (2)
- censorship (11)
- Chemistry (1)
- Cheney (1)
- Christmas (1)
- Church (4)
- CIA (2)
- Coast (1)
- comic (1)
- composites (1)
- Computing (31)
- Congress (6)
- Conservative (6)
- Cooking (1)
- Corporate stupidity (12)
- Creationism (13)
- cronyism (3)
- Customer Service (1)
- Dallas (1)
- Danielle Dax (1)
- Database (1)
- DEA (1)
- Dead Link (5)
- death (3)
- Dell (1)
- Diabetes (88)
- Diebold (1)
- diesel (2)
- Disney (1)
- DMCA (2)
- DNA (19)
- DNS (2)
- Doctors (2)
- dolphin (1)
- Don McLeroy (7)
- Drugs (4)
- Dual CPU (1)
- Duke Ellington (1)
- dvd (1)
- education (11)
- Eggs Benedict (1)
- Electric Velomobiles (1)
- Endangered Species (4)
- Ethics and Science (8)
- Evolution (30)
- exercise (54)
- fallacies (1)
- family (3)
- FCC (1)
- FDA (1)
- FEMA (3)
- Fiesta (1)
- FollowUp (4)
- food (7)
- Football (1)
- Fox News (1)
- Fraud (14)
- free piston (1)
- Freeware (1)
- friends (1)
- Fundamentalist (4)
- Fusion (1)
- Gardening (1)
- generator (1)
- Genes (4)
- Genetics (8)
- Genome (11)
- global warming (3)
- Global Warming and Climate (3)
- Go Go's (1)
- Google (5)
- Google Search (1)
- GOP (14)
- Greg Abbott (1)
- Grover Norquist (1)
- Guns (3)
- Hakiu (11)
- Halbach (1)
- Hard Drive (2)
- Hawaii Trip (1)
- HDTV (1)
- health (2)
- health care (1)
- Hezbollah (1)
- High School (6)
- Hillary Clinton (1)
- History (2)
- HIV (3)
- Homecoming (1)
- honor killings (1)
- house (1)
- HP (4)
- HPV (2)
- Hub motor (1)
- Hubble (1)
- human (2)
- Hunger (1)
- Hutto (1)
- id (3)
- Impeachment (8)
- Indonesia (1)
- intelligent design (6)
- Internet (4)
- Investigations (8)
- IPv6 (1)
- Iraq War (9)
- Islam (7)
- ISP (10)
- Jade (1)
- Janeane Garofalo (2)
- Japan (1)
- jazz (1)
- Jefferson (1)
- Johnny Cash (1)
- Karl Rove (3)
- Knol (1)
- law inforcement (5)
- learning (2)
- Led Zeppelin (1)
- leds (6)
- linguistics (1)
- Linux (2)
- lobbyist (4)
- logic (2)
- lying (1)
- magnets (1)
- Manga (2)
- Mars (3)
- math (2)
- McCain (4)
- me (5)
- Media (1)
- Medicine (2)
- Mexico (1)
- Microsoft (7)
- Middle East (1)
- Military (2)
- Minolta (1)
- motor (2)
- motorcycle (2)
- Mpeg4 (1)
- music (29)
- Mythbusters (1)
- Nancy Sinatra (3)
- NASA (1)
- Neandertal (1)
- Network neutrality (3)
- networking (2)
- NewEgg (1)
- NPR (1)
- NSA (1)
- Nuclear power (1)
- Obama (3)
- okonomiyaku (1)
- Open Source (3)
- OpenVPN (1)
- OS (5)
- OTEC (1)
- Outlook (1)
- Overclocking (1)
- Oversite (12)
- Palin (4)
- Palin lied (3)
- Patent (1)
- Perception (1)
- Personal (2)
- Pete Gallegos (1)
- Phillip Bloom (1)
- Philosophy (1)
- Photography (6)
- Photoshop (1)
- Physics (4)
- Plame Affair (2)
- Plants (3)
- plasma (1)
- Politics (40)
- Politics and Science (6)
- Programing (3)
- Public Policy (8)
- quote (3)
- Recipe (1)
- recumbent (1)
- Red One (1)
- Religion (33)
- Republican (56)
- Republican War on Science (8)
- Review (2)
- RFID (1)
- RIAA (1)
- Rice (1)
- Richard Dreyfuss (1)
- RMA (1)
- RNA (3)
- robot (2)
- Round Rock (1)
- RV (1)
- San Antonio (1)
- SAT (1)
- Science (22)
- science fiction (1)
- ScribeFire (1)
- Seagate (1)
- Sears (1)
- Seti (1)
- sex (2)
- Shopping (6)
- Skepticism (2)
- Slide Show (12)
- software (7)
- Solar power (2)
- Sony (1)
- Space and Cosmology (2)
- Spacecraft (2)
- Speeches (2)
- Sprinter Van (2)
- Stellarator (1)
- Stem Cells (1)
- Stirling (1)
- stupidity (27)
- Supercomputer (1)
- Superfoods (1)
- T. Rex (3)
- Tabacco (1)
- Tandem (4)
- tea (1)
- Technology (2)
- Terrorists (8)
- Test (1)
- Texas (15)
- TFT (1)
- Time Warner (3)
- Tom DeLay (3)
- Toy (1)
- Trade (2)
- Transportation (1)
- TRC (1)
- trees (1)
- trike (1)
- Trips (1)
- US (4)
- US Budget (2)
- V-Strom (1)
- video (53)
- Vista (137)
- Vitamins (1)
- VNI (2)
- waybacked (1)
- WD MyBook (1)
- Weather (3)
- Web Comic (1)
- Wedding (1)
- Whoopi (1)
- Wiki (5)
- wind power (1)
- Windows 7 (1)
- wireless (2)
- worms (1)
- WWW (1)
- X-Mass (1)
- XP (1)
- YouTube (1)
No comments:
Post a Comment