Showing posts with label black hat conference 2012. Show all posts
Showing posts with label black hat conference 2012. Show all posts

Windows 7 lags Windows 8 in terms of security



The precise details of what they discovered were barely within the realm of my comprehension. Apparently many doubly-linked lists within Windows 8 are now protected by "pool cookies." To avoid exploits that involve forcing arbitrary code or data into places it doesn't belong, Windows 8 randomizes locations for memory allocation and adds "guard pages" as needed. That sort of thing.



Researchers Chris Valasek (Senior Security Researcher at Coverity) and Tarjei Mandt (senior vulnerability researcher at Azimuth Security) spend their days seeking ways to compromise security in Windows. They're good guys; if they find a problem they report it, rather than exploiting it for illicit gain. At the Black Hat conference they reported on their analysis of new low-level security features in Windows 8.



In between slides filled with code and intense details, Valasek and Mandt displayed a couple that anybody could understand. The column for Windows Vista was all red, meaning not secure. Windows 7 was close, with just a few green checkmarks. And of course Windows 8 displayed a column of solid green checkmarks. Expert or not, we know that green is good.


After the talk I checked in with Valasek.
Rubenking: Back in the day I would write TSR (Terminate and Stay Resident) programs in DOS, and they were great, and useful. But the malware writers used the same DOS features to write bad stuff. Microsoft could have shut them down, but they would have shut me down too. It seems from your talk like they don't plan to shut anybody down. They're doing fine-tuning, working really hard to ensure that everything still works while they crank up security. Do you think it's conceivable you could write an operating system that just wouldn't be vulnerable to attack?


Valasek: No, that doesn't exist. Not as long as humans are writing the code. Once Skynet takes over and humans don't write code any more that might be possible. They have to have a certain amount of data and algorithms and structures that are needed, so there's always a potential to use this stuff for exploitation purposes. Here's the thing. If you don't make it impossible, but you make it severely difficult so only a tenth of one percent of the population can do it, you've effectively lowered the threat to decent levels.


Rubenking: And if you hire that one tenth of one percent…
Valasek: That's just what Google and Microsoft have done. Hire that one tenth of one percent, then you're good.
Rubenking: Thank you Chris!
Indeed, Windows 8 isn't perfect. Valasek and Mandt laid out a number of possible avenues that hackers might conceivably exploit. But as Valasek said, it will be severely difficult, and only the most adept will come close to exploiting the tiny vulnerabilities that remain.

Black Hat Conference 2012-- NFC (Near Field Communication)- Security Breach in Android


"Specialist uses NFC(Near Field Communication) to attack android smartphones... - a loophole in android security .."


Recently researchers at Black Hat Security Conference, held at Las Vegas, reveals the security loophole in android smartphones..

Experts demonstrated the security breach of delivering malicious softwares and code using a new latest revealed features named Near Field Communication(NFC).NFC is already present is recently launched devices such as Samsung Galaxy S3 and HTC one X.


Security flaws arises using NFC by jst placing the device few centimeters away from the hacked device , and the job is done ..!!
Complete data including photos contacts and even payment related transactions can be affected using NFC.This can be done by simply deploying hidden reader to snatch the data, from an NFC-enabled card in someone's pocket by swiping a reader very close to the card.


Another gap in android security was availed by Charlie Miller (reasearcher at Accuvant). Which implements the replacing of a tag of a website which ws functioned to direct to the some other page , by a tag which would redirect to the malicious website and may compromise your phone in terms of protection.


They also figured out the way to design the device which can easily do the job for you ..
Experts further added , this postage stamp sized device could be placed at crowdy public places and when the device holder passby , the phone is highjacked without any any user interaction.


So better beware of your surrounding ...You can also be Victim of NFC-Jacking ...!!


The only best possible solution is to Disable NFC via setting menu/widget when not in use.




 
© 2009 windows 8 download free Software | Powered by Blogger | Built on the Blogger Template Valid X/HTML (Just Home Page) | Design: Choen | PageNav: Abu Farhan