|
|
|
Microsoft MSE safe from Windows kernel hook attack |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Microsoft MSE safe from Windows kernel hook attack Par SecurityLe [2010-05-13] à 16:46:28
Présentation : Microsoft Security Essentials MSE , the software giant's free antimalware solution, is one of the few products that is not affected by the recently rediscovered method for disabling security software on Windows. MSE does not use SSDT hooks, so its real-time protection cannot be disabled via this method. When the report was first published, we noticed that MSE was not on the list of affected products and contacted Microsoft for clarification. Microsoft is aware of research published by Matousec and we are investigating the issue, a Microsoft spokesperson told Ars. Based on available information, we do not believe our products are affected due to the design of our real-time protection. We are working to confirm this. Microsoft said someone would get back to us, but we figured it would be quicker to go straight to the source. As we assumed, MSE does not implement any hooks and hence it can not be attacked by KHOBE technique, a Matousec spokesperson told Ars. It might be confusing when you read various media comments on KHOBE research that mention that all antivirus products are vulnerable, but they miss the most important thing, which is that only software that implements hooking can be vulnerable. Only some antivirus products implement hooks but many antivirus products do not use hooks at all. The major group of software that is affected are not antivirus products but HIPS Host Intrusion Prevention System software, behavior blockers, various Internet Security Suites with host protection features etc. Update Microsoft has worked directly with Matousec to confirm that Microsoft Security Essentials and Forefront Client Security products are not affected by their KHOBE research due to the design of our real-time protection, a Microsoft spokesperson eventually followed up with. Microsoft insists that security companies avoid using kernel patches in their software. It would be therefore rather hypocritical of Microsoft to use such hooks. Furthermore, self-defense techniques, which are usually implemented using hooks, are not common part of Microsoft's solutions. It's worth noting that Microsoft listened to security vendors and in Windows Vista and Windows 7 implemented several new documented methods to let products include self-defense mechanisms. Unfortunately, there is nothing forcing vendors to use these new methods as their old hooking-based protection still works in new versions of Windows. This is why the list of products affected is so lengthy. Matousec is continuing to update the list, and at the time of publishing, there were 35 vulnerable products. This is another big win for MSE, which has received very positive feedback ever since its release. Read the comments on this post
Les mots clés de la revue de presse pour cet article : microsoft windows kernel attack Les videos sur SecuObs pour les mots clés : microsoft windows attack Les mots clés pour les articles publiés sur SecuObs : microsoft windows Les éléments de la revue Twitter pour les mots clé : microsoft windows kernel attack
Les derniers articles du site "Security" :
- Using ASAN as a protection - Execute without read - Together, we can make a difference - Internet Bug Bounty issues its first 10,000 reward - vtable protections fast and thorough - Exploiting 64-bit Linux like a boss - Exile for the BBC Micro some elegant solutions - Using ASAN as a protection - Execute without read - Together, we can make a difference - Internet Bug Bounty issues its first 10,000 reward - vtable protections fast and thorough - Exploiting 64-bit Linux like a boss
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|