- It's the applications, stupid
- Will a whitelist save personal computing?
- Thousands of Web sites under attack
- To solve the unsolvable problem
- Re-thinking the security of virtual machines
- Security Development Lifecycle trumps code complexity
- Is your Web site FIPS compliant?
- Computer security: Why have least privilege?
- Strategic security: Get a handle on authentication
- Control user installs of software
August 05, 2006 | Comments: (0)
Vista Security Bug Found at Blackhat...Not!!
Several "news" sources are reporting that a new bug in Vista security was released at Blackhat one day later in response to Microsoft's challenge to hack Vista. It's not the facts.
This is a well known bug ("the Blue Pill") that many of us have known about for quite some time. The founder has even been writing and presenting on it for many months.
http://theinvisiblethings.blogspot.com/2006/06/introducing-blue-pill.html
It's been in the media for quite some time, and even my InfoWorld editor asked me to write a piece on it a few months ago (I declined because I wanted to get a better understanding of it after her Blackhat presentation).
The researcher has had conversations with Microsoft for many months and she announced she would publicly reveal it at Blackhat many months ago. Microsoft, I, and many, many mailing groups have been discussing Blue Pill for months. Microsoft even likes her and considers her to be one of the good guys (er...girls).
Like other malware code of its ilk, you must run an executable in pure
Administrative mode, which doesn't happen by default in Vista. So, any
exploit that starts with the words...you run an untrusted, unsigned
executable as Administrator, to get it to work...what exploit wouldn't work at that point?
What is interesting about this exploit is that she is able inject malware that comes undetectable using current detection methods. That's the take away.
This was not a one day bug found in response to Microsoft's Vista challenge at Blackhat.
Posted by Roger Grimes on August 5, 2006 12:28 PM
RATE THIS ARTICLE:
-

- COMMENTS
TOP STORIES
Hyperconnected users growingSteve Jobs to keynote WWDC
CSC settles kickbacks case
MS previews SMB software
What does HP-EDS really mean?
Mac Office 2008 SP1 released
HP buys EDS for $13.9 billion
Corporate IT spending slows
MS targets smartphone market
Sun to clarify JavaFX plan
ADDITIONAL RESOURCES

- Application Security: Threats and How to Counter Them
- Why Linux Threats Mean Business
- Minding the Machines: PC Disaster Recovery for the Enterprise

- Protect Your Data with SSL
- Prevent Your Next Microsoft Exchange Outage
- 11 Myths About Microsoft Exchange Backup & Recovery





