CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image DEP not a 'total solution' to WMF image
CastleCops
According to Kaspersky Labs hardware Data Execution Protection (DEP) only helps to prevent successful exploitation, it doesn't completely mitigate it.

Hardware-based DEP is currently only available on NX-bit (AMD) and XD-bit (Intel) enabled CPUs, running Windows XP with SP2.

"We've tested on AMD and Intel platforms and HW DEP seemed initially to prevent successful exploitation in Internet Explorer and Windows Explorer. However, when testing the latest builds of third party image viewers like Irfanview and XnView HW DEP didn't prevent exploitation, even with HW DEP enabled for all programs. This is because both Irfanview and XnView are packed with ASPack and Windows disables HW DEP for ASPack packed files."
More alarming is using a limited user account, which restricts NTFS permissions doesn't protect the user from this exploit.

Windows 2000 which is by default not vulnerable to this exploit can be made to be vulnerable by simply using a third party image viewer like Irfanview or XnView because the viewers require the vulnerable file to show .wmf files.

Windows XP Pro 64 Bit has also been found to be vulnerable to this exploit. However currently the code cannot be executed because it is written for 32 bit systems. In order for the vulnerability to be exploited on a 64 bit system new shellcode specific to x64 is required. Kaspersky feels this is a remote possibility as there are only a small number of users which run 64 bit systems, so the vulnerbility couldn't be exploited on a large scale.
Posted on Wednesday, 04 January 2006 @ 14:39:24 UTC by Robin (4702 reads)
[ Trackback ]
image

"DEP not a 'total solution' to WMF" | Login/Create an Account | 3 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: DEP not a 'total solution' to WMF (Score: 1)
by MedTxInMich  on Wednesday, 04 January 2006 @ 17:02:57 UTC
(User Info | Send a Message)
So, what exactly does this mean to 2000 users? Does this mean that the patch I just downloaded isn't going to protect me? I'm afraid I don't understand. Layperson's terms, please?

Thanks,
Carol
Who only understands medical jargon ;-)


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· Intel
· HotScripts
· W3 Consortium
· CastleCops
· More about CastleCops
· News by Robin


Most read story about CastleCops:
Acceptable Use Policy

block bottom
Article Rating
spacer
Average Score: 1
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer