Security pros completely bypass Vista's now "useless" security

Sat Aug 9, 2008 7:53PM EDT

See Comments (8)

About all those fancy security measures Microsoft put into Windows Vista... well, they're now pretty much useless, according to security experts from IBM and VMware presenting a new attack methodology at this week's Black Hat security conference.

The details of the latest attack are complicated to explain, but they essentially outline ways to use .NET, Java, and Microsoft's ActiveX system to bypass Vista's security via a web browser. Any browser can be used, but Internet Explorer makes the security bypass even easier, letting an attacker insert data into a running machine at any place he chooses. The researchers note that the attack doesn't exploit any new vulnerability in Vista but rather takes advantage of the architecture of the OS and the way Windows tends to trust code fragments. In broad terms, if one component of Windows trusts a piece of code, for example, and passes it on to another component, then that second component will often automatically trust the code too, and so on. Browsers are increasingly being seen as the easiest "way in" for malware.

While this initial round of attacks focuses on Vista, the potential exists for a similar exploits to be fashioned against other operating systems, too, both older versions of Windows and even non-Microsoft OSes.

The full paper outlining the security risk is available here, but as I write this the site is offline due to heavy traffic.

It's important to note that this is a brand new exploit and has not yet been taken advantage of by any real world attack. The best advice until Microsoft responds is to make sure your standard antivirus and antispyware software is up to date and active: Third-party security systems should still be able to detect malicious code through traditional scanning means.

LINK: Windows Vista security 'rendered useless' by researchers

Comments on Security pros completely bypass Vista's now "useless" security

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 6 Posted by gullwingdoors on Thu Sep 3, 2009 4:14PM EDT Report Abuse

    Forget Windows OR Mac. Just use Linux. Give Ubuntu a try.

  • 7 Posted by jseyfield on Thu Sep 3, 2009 4:43PM EDT Report Abuse

    @ Mac person: Mac will have the same problems as its market share grows. It's just a matter of time. @Linux person: How come nobody ever mentions that it's not a cakewalk switching to Linux? Everyone makes it sound so simple. Well it's not, I know I checked it out. Frankly I just thought Linux was just one system, not a family with dozens of different choices for different users.

  • 8 Posted by werul2000 on Thu Sep 3, 2009 10:43PM EDT Report Abuse

    i have had vista home basic since november 2007 and since december haven't been able to update a thing so to me vista isn't worth crap. i appears i aren't the only one with this problem and to date no one i know how to fix it

More Posts: First Prev 1 2 Next Last

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.