5 ms·
Windows hole discovered after 17 years
- Mark_B 17y ago"Discovered" or "finally made public" after 17 years. Security holes are in a lot of things, but I can't believe that this wasn't found sooner by people who would use it for nefarious purposes and kept under wraps.
- ars 17y agoI wonder if this affects OS/2 as well.
- DocSavage 17y agoIt's also interesting that the exploit was found by a Google employee who was designated #1 in the top 15 Most Influential People in Security. http://www.eweek.com/c/a/Security/The-15-Most-Influential-People-in-Security-Today/1/ http://www.eweek.com/c/a/Security/The-15-Most-Influential-Pe... With the resources both Google and Microsoft have at their disposal, I wonder if it's worth having a few employees discovering security flaws in your opponent's platform.
- pbhjpbhj 17y agoKnowing about opponents security flaws is an awesomely powerful publicity/propaganda tool. MS release something on how IE8 is just as secure as Chrome (browser) and Google counter-release how it's got a hole the size of the Great Rift that's been inherited right back from IE6...
- tptacek 17y agoNo, I really doubt Google would do that. For one thing, it's not done. For another, Google would lose that fight, badly; they are severely outgunned on this front.
- pbhjpbhj 17y agoWhy is it not done to call out opponents when they make huge claims that are patently not true? Haven't Mac used this in their "I'm a Mac" advertising campaign (albeit hiding behind "PC" rather than saying "Windows PC"). Google would lose because they make big claims about security and their opponents know about lots of security flaws??
- tptacek 17y agoWhat's not done is for software vendors to drag out specific vulnerabilities --- I would say "particularly vulnerabilities they themselves uncovered", but that's never happened --- and use them to market competing software. Why? Because Google and Microsoft have a lot more to fear from 4 person companies spending 90% of their time researching vulnerabilities than they do from each other, and waving flaws around as if they were some kind of point score concedes a huge marketing point. Google would lose because Microsoft outspends Google significantly on vulnerability research. This particular arms race is never going to happen, but if it did, Microsoft would win it.
- rbanffy 17y ago"but if it did, Microsoft would win it." There is a difference. It's much easier to upgrade Google's applications than Microsoft's. When Google patches Gmail, it takes a couple minutes for me to enjoy my corrected version. When Microsoft issues a correction, it could take weeks until it hits the Windows Update servers and that could easily turn into months before many businesses incorporate it into their update sets. It's not only the size of the attack surface, but the time it remains open. There is also a huge factor in public perception - people perceive their computers as imperfect mostly because they are astonishingly unreliable. If Google can make people happier with their computers and web applications than they are with Windows and desktop apps, Microsoft will have a huge problem that may not be solvable by throwing money and people at it.
- btilly 17y agoI would guess the value proposition is more a case of worrying about ...security flaws in software used on your network rather than ...security flaws in your opponent's platform.
- tptacek 17y agoI'm pretty sure Google didn't sic Tavis on Microsoft; this is a logical extension of work he's been doing for years.
- jsz0 17y agoFor a company like Google it would probably be worth doing just to make sure all those Windows PCs stay online and continue to access Google services/advertisements. Imagine a truly malicious exploit that knocked 10-15% of Windows computers offline instead of joining them to a bot net. Even if only half of those computers were previously accessing Google services they would see a big hit in advertising revenue.
- nanijoe 17y agoWhat else did they find? That DOS has problems with memory management? Advances in technology are bound to expose flaws in older products, so what's the news here?
- btilly 17y agoDid you read the article? The hole exists in all 32-bit versions of Windows, up to and including Windows 7. So this affects current products. And affects virtually every Windows machine in use on virtually any corporate network. The only good thing about it from the description is that it is a local privilege escalation only.
- mfukar 17y agoIt's a flaw that affects recent products.
- ams6110 17y agoI don't think this is a bad observation. My slant on it is, if you are maintaining backwards compatibility to a point in time where these things just didn't matter, because only one person used the machine, there were no multiple user accounts, and the machine was not on a network... it's unsurprising that such an environment would be rife with security holes. Not saying it'a acceptable, just that it's not surprising. Edit: and it appears there's an effective way to mitigate this, disable the 16-bit support in group policy.
- tptacek 17y agoIn that sense Unix retains compatibility with the '70s. Operating systems are rife with security flaws. Uniformly.
- rbanffy 17y agoMaybe, but the kind of backwards compatibility Windows offers is very unique. It's like being able to run Apple III software natively on a modern Macintosh. ;-) I think IBM can provide a mainframe fresh off the assembly line that can run 70's software. Most amazingly, many do.
- tptacek 17y agoThis is Tavis's "thing" (one of them, at least); he's better known for fuzzing the device virtualization code in VMware and Xen and finding hypervisor escapes. I'm not even a little surprised that he found privilege escalation in VDM. It's a cool bug, but it's a bit strange to see it get written up like this, because it doesn't matter a whole lot. On most Windows machines, if you have a normal user account, you have everything you need; in corporate environments, if you have one admin password you probably have all of them; in servers, the user account you bust is probably a local admin.
- tptacek 17y agoAlso: very worth reading Tavis' advisory: http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0346.html http://archives.neohapsis.com/archives/fulldisclosure/2010-0... This is an awesome bug; he had to use CreateRemoteThread to jump into a process with special permissions, then exploit the difference in the way segment selectors are handled from normal 32 bit code and simulated real mode, and finally write code that would make the iret instruction fail to get a trap frame to play with.
- TallGuyShort 17y agoTheir update states that their is no Group Policy Manager outside of Windows 2003 - however the "God Mode" hack for Windows 7 supplies this option without the need for messing with registry keys. Just create a folder on the desktop with the name "GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}" and the Group Policy Manager can be access under "Administrative Tools".