Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 06-08-2006, 06:34 AM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Aug 2006
Posts: 1
Default Vuln Researchers Aiming In A Different Direction

Vuln Researchers Aiming In A Different Direction

By Aelphaeis Mangarae [irc.efnet.org #d-u] [adm1n1strat10n AT hotmail DOT com]
SecurZone [http://SecurZone.org] IT Sec Articles
6th of August 2006

Easy to find flaws in operating systems are disappearing. Vulnerability researchers have started to focus on finding flaws in Drivers and other applications.

During a presentation, two researchers from the security firm Matasano presented the results of their research on common software agents included on many enterprise computer systems.

The two researchers, David Goldsmith and Thomas Ptacek, found numerous vulnerabilities in the agents designed to handle automatic updating, schedule backup tasks and handle support requests, the researchers said.

In another presentation, two other researchers - SecureWorks flaw finder David Maynor and "johnny cache" - showed off a method of compromising laptop computers through flaws in the wireless drivers installed on the machine.

"Now that the OS layer is harder to crack, you are seeing a lot more people going higher up the stack, to applications, or lower, to device drivers," Maynor said.

"The amazing thing is that the vulnerabilities we found were simple, they were 1993 vulnerabilities," he said. "These have clearly not been looked at before. We are talking straight-up stack overflows-the first thing that someone would test for if they were doing an audit."

I would say it is likely the main reason vulnerabilities such as stack overflows are harder to find in operating system components is because of stack and heap overflow protections implemented in some operating systems. Such as Microsoft Windows XP Service Pack 2.

Since researchers are now shifting more of their effort into discovering vulnerabilities into find vulnerabilities in drivers and applications will we will stack and heap overflow protections implemented into device drivers and applications?

http://www.securzone.org/community/i...?showtopic=662
Aelphaeis_Mangarae is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 06-08-2006, 07:16 AM   #2 (permalink)
In The Zone
 
Venom's Avatar
 
Join Date: Jun 2006
Posts: 240
Default Re: Vuln Researchers Aiming In A Different Direction

Yeah this was revealed in that BH conf, good to see :]
__________________
From now on we are poison to you, that's why we call ourselves, the Venom!
Venom is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +5.5. The time now is 12:06 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2