Feeds

Microsoft 24 hours late with IE8 pwn protection

What a difference a DEP makes

Top 5 reasons to deploy VMware with Tegile

Just one day after a little-known hacker dazzled his peers by exploiting the latest version of Internet Explorer 8 beta, Microsoft added an important protection to the browser that probably would have prevented the attack.

The measure, which was added to last Thursday's final release of IE8, restores so-called ASLR, or address space layout randomization, and DEP, or data execution prevention, to the Microsoft browser. Microsoft has more about that here.

Those protections, which made it harder for attackers to remotely execute malicious code after finding software bugs, were seen as a sea change when Microsoft added them to IE7. Then security researchers rained on Microsoft's parade last summer when they unveiled several methods to bypass the measures.

Nils, the German hacker who felled IE8 during last week's Pwn2Own hacker conference, hasn't said exactly how he managed to pull off the IE8 hack. Indeed, contest rules forbid contestants from divulging such information. But when asked in an interview by Ryan Naraine if he used Dowd and Sotirov's method, Nils smiled and responded: "I really appreciated their work."

What's more, fellow Pwn2Own contestant Charlie Miller says he remembers Nils admitting he used the Sotirov/Dowd technique at the competition to successfully exploit IE. Miller says he's sure of that because he was dying to know how Nils (who declined to share his last name) managed to penetrate the IE fortress.

"It was pretty powerful in the sense that without that technique no one knows how to get your code to execute in IE," Miller told The Reg. "It turns out he exploited (the) beta version of IE8 (that) hadn't done that fix."

Terri Forslof, manager of security response at Tipping Point Technologies, which sponsors Pwn2Own, said she couldn't comment on the speculation ahead of a blog post she planned to publish soon. We did, however, manage to pry a single sentence from her otherwise tight lips: "The released version of IE8 will most likely prove to be considerably more difficult to exploit on Vista, but with the other platforms all bets are off."

That's consistent with what we know about the ASLR, which only works when later versions of IE are running on top of Vista or Windows 7, which is still is beta. DEP only works on Windows XP, Service Pack 3 and later, a Microsoft spokeswoman said. (An earlier version of this story incorrectly said DEP was available for only for Vista and later.)

If the speculation proves correct, it means one of the safer ways to browse the internet is by using IE8 on Vista or Windows 7. At least for now. As the this episode demonstrates, software security is a fluid thing. A single new attack method from the bad guys or countermeasure by the white hats makes all the difference. Which is why this debate won't be settled anytime soon. ®

Remote control for virtualized desktops

More from The Register

next story
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Mozilla, EFF, Cisco back free-as-in-FREE-BEER SSL cert authority
Let’s Encrypt to give HTTPS-everywhere a boost in 2015
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Mitigating web security risk with SSL certificates
Web-based systems are essential tools for running business processes and delivering services to customers.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.