The Active Network
ActiveWin Anonymous | Create a User | Reviews | News | Forums | Advertise | Career Portal | Users Online: 315  
 

Sponsors: Search Engine Optimisation
exterminator
lawn care
Search Engine Optimisation
Search Engine Optimization
Search Engine Marketing
PPC Management
Search Engine Optimization
Search Engine Optimisation
search engine optimisation
Cheap Web Hosting
Webanalyse
online credit card processing
Lenovo Laptops
Text Links
Business Gifts
SEO Services
SEO
Chat
Search Engine Optimization
SEO Consult
Demand Generation Software
Celebrity Autopsies
Network Software

neowin.net

Amazon.com

  *  

  More details on the Pwn2Own Flash flaw that won the Vista machine
Time: 16:09 EST/21:09 GMT | News Source: ZDNet | Posted By: Jonathan Tigner

So, I’ve been pretty surprised by the response to the discussion of the Flash flaw that allowed the Vista machine to be compromised in the Pwn2Own contest. I’m working on getting an interview with Alexander Sotirov and Shane Macaulay (see image, courtesy of ZDI’s official site) to discuss the issue, but in the meantime, I think we can make some reasonable assumptions from the details that have been released in an InfoWorld article:

Macaulay, who was a co-winner of last year’s hacking contest, needed a few hacking tricks courtesy of VMware researcher Alexander Sotirov to make his bug work. That’s because Macaulay hadn’t been expecting to attack the Service Pack 1 version of Vista, which comes with additional security measures… For those who aren’t familiar with Sotirov, he’s of the Javascript Fung Shui fame, which is basically a new method of heap spraying that allows the exploit code to have a predictable target address where it will be located in the heap.

So they team up and get to work:

Under contest rules, Macaulay and Miller aren’t allowed to divulge specific details about their bugs until they are patched, but Macaulay said the flaw that he exploited was a cross-platform bug that took advantage of Java to circumvent Vista’s security.
Hmmm… does this sound familiar to anyone? See my posts (part 1 here and part 2 here) on the flaws that John Heasman spoke of in Java which require it to turn off features like DEP in operating systems that provide these protections.

Write Comment
Return to News

  Displaying Comments 1 through 0 of 0
  The time now is 3:33:30 PM ET.
Any comment problems? E-mail us

Be the first to write a comment on this story!


Write Comment
Return to News
  Displaying Comments 1 through 0 of 0
  The time now is 3:33:30 PM ET.
Any comment problems? E-mail us
Please Enter Your User name and password:

Sign Up For A User Name

 

  *  
  *   *