Feeds

Microsoft 24 hours late with IE8 pwn protection

What a difference a DEP makes

High performance access to file storage

Just one day after a little-known hacker dazzled his peers by exploiting the latest version of Internet Explorer 8 beta, Microsoft added an important protection to the browser that probably would have prevented the attack.

The measure, which was added to last Thursday's final release of IE8, restores so-called ASLR, or address space layout randomization, and DEP, or data execution prevention, to the Microsoft browser. Microsoft has more about that here.

Those protections, which made it harder for attackers to remotely execute malicious code after finding software bugs, were seen as a sea change when Microsoft added them to IE7. Then security researchers rained on Microsoft's parade last summer when they unveiled several methods to bypass the measures.

Nils, the German hacker who felled IE8 during last week's Pwn2Own hacker conference, hasn't said exactly how he managed to pull off the IE8 hack. Indeed, contest rules forbid contestants from divulging such information. But when asked in an interview by Ryan Naraine if he used Dowd and Sotirov's method, Nils smiled and responded: "I really appreciated their work."

What's more, fellow Pwn2Own contestant Charlie Miller says he remembers Nils admitting he used the Sotirov/Dowd technique at the competition to successfully exploit IE. Miller says he's sure of that because he was dying to know how Nils (who declined to share his last name) managed to penetrate the IE fortress.

"It was pretty powerful in the sense that without that technique no one knows how to get your code to execute in IE," Miller told The Reg. "It turns out he exploited (the) beta version of IE8 (that) hadn't done that fix."

Terri Forslof, manager of security response at Tipping Point Technologies, which sponsors Pwn2Own, said she couldn't comment on the speculation ahead of a blog post she planned to publish soon. We did, however, manage to pry a single sentence from her otherwise tight lips: "The released version of IE8 will most likely prove to be considerably more difficult to exploit on Vista, but with the other platforms all bets are off."

That's consistent with what we know about the ASLR, which only works when later versions of IE are running on top of Vista or Windows 7, which is still is beta. DEP only works on Windows XP, Service Pack 3 and later, a Microsoft spokeswoman said. (An earlier version of this story incorrectly said DEP was available for only for Vista and later.)

If the speculation proves correct, it means one of the safer ways to browse the internet is by using IE8 on Vista or Windows 7. At least for now. As the this episode demonstrates, software security is a fluid thing. A single new attack method from the bad guys or countermeasure by the white hats makes all the difference. Which is why this debate won't be settled anytime soon. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.