Microsoft .NET is a powerful platform for building flexible, reliable and connected solutions that have visually stunning user experiences, seamless and secure communication, and the ability to model a wide range of business processes. As our Microsoft .NET team is anxious for researching new software releases, testing new technologies and attending technical seminars it is our great privilege to share news and findings we discover along our way.
Install Mac OS X on Intel/AMD PC using iATKOS v7
How to remove "showing post with label" in Blogger
How to add Google Buzz to Blogspot blog
Chat live with your blog visitors using Yahoo Pingbox
Install Mac OS X on Intel/AMD PC using iATKOS v7
Description goes here, this is just a test description....read more
How to remove "showing post with label" in Blogger
Description goes here, this is just a test description....read more
How to add Google Buzz to Blogspot blog
Description goes here, this is just a test description....read more
Chat live with your blog visitors using yahoo
Description goes here, this is just a test description....read more
Thursday, January 21, 2010
Microsoft confirms an ancient Windows bug
The company warned users that a bug in a kernel, which counted more than 17 years could be used by hackers to crack PCs.
The vulnerability in the Windows Virtual DOS Machine (VDM) subsystem. The VDM subsystem was added to Windows with the July 1993 release of Windows NT, Microsoft's first fully 32-bit operating system. VDM allows Windows NT and later to run DOS and 16-bit Windows software.
The advisory spelled out the affected software on all 32-bit editions of Windows, including Windows 7, and told users how to disable VDM as a workaround. Windows' 64-bit versions are not vulnerable to attack.
"An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode," said the newest advisory. "An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."
Jerry Bryant, a program manager with the Microsoft Security Response Center (MSRC), said that the company had not seen any actual attacks using the vulnerability, and also downplayed the threat if hackers do exploit the flaw. "To exploit this vulnerability, an attacker must already have valid logon credentials and be able to log on to a system locally, meaning they must already have an account on the system," Bryant said in an e-mail.
Tuesday, September 29, 2009
The new attack code poses a threat on Vista users, while Windows 7 and XP crack-resistant.
Although this vulnerabilty issue has been known since Spetember the publicly available programs that can use that bug haven't been able to do anything except crash the operating system. However, a new attack code developed by Harmony allows to run unathorized software on cracked PC making it much more serious problem for Microsoft. The attack code was added to the company's open-source Metasploit penetration testing kit making the code widely available.
From other side, a software company called Immunity recently developed its own attack code for the bug, but that code is available only to the company's paying subscribers. And although the atack code is claimed to potentially work on both Windows Vista and Windows 2008 (Service Pack 1 and 2) the code may not be completely reliable, according to Immunity Senior Researcher, who stressed that he could get the Metasoft Attack to work only on the Windows Vista operating system running within a VMware virtual machine session. He added "When he ran it on native Windows systems, it simply caused the machines to crash."
In turn a Metasploit developer said that the attack definitely worked on at least some physical machines, but looks like it could use more testing.
Either way, the public release of this code should put Windows users on alert. Security experts worry that this code could be adapting to create a self-copying worm attack, much like last year's Conficker outbreak. It might seems strange but unlike Conficker, this attack would not affect older Windows XP, Windows Server 2003,or Windows 2000 systems. That's because the underlying flaw that all of these programs exploit lies in the SMB (server message block) version 2 system, introduced firstly in Vista.
Microsoft has confirmed that Immunity's attack works on 32-bit versions of Vista and Windows Server 2008, but did not have any immediate comment on the Metasploit code.
According to Immunity Senior Researcher the flaw has been patched in Windows 7, yet Microsoft released a Fix tool that disables SMB 2, and the company said that it is working on a fix for the software.
Install Mac OS X on Intel/AMD PC using iATKOS v7
How to remove "showing post with label" in Blogger
How to add Google Buzz to Blogspot blog
Chat live with your blog visitors using Yahoo Pingbox
Install Mac OS X on Intel/AMD PC using iATKOS v7
Description goes here, this is just a test description....read more
How to remove "showing post with label" in Blogger
Description goes here, this is just a test description....read more
How to add Google Buzz to Blogspot blog
Description goes here, this is just a test description....read more
Chat live with your blog visitors using yahoo
Description goes here, this is just a test description....read more