ZDNet Resources
- XP SP3: Now on Windows Update
- XP SP3: Now on Windows UpdateVirus attack the header exclusivelyFor file conversion the header is renamed.Header is CPU,BIOS and so on.The header identifies the file type,CPU speed and BIOS settings.The header resides in the L1 cache.Only hackers can access the header.Don't see anything in it I need.So I guess I'll...
- Tags: OPEN SOURCE, SECURITY, Microsoft Windows, header, F/OSS, flaw, Microsoft Windows Update, Microsoft Windows XP
- Discussion threads 2008-05-06
- Word up to Linux fan boys: Multiple Linux Flaws show that Linux also has kernel issues
- Word up to Linux fan boys: Multiple Linux flaws show that Linux also has kernel issuesLet's find out.I'd like to know just what the similarities or lack there of will be in security issues when Linux replaces Windows as the OS of the people.Apple's dealing with this right nowTime to...
- Tags: Operating systems, UNIX, OPEN SOURCE, SECURITY, Microsoft Word, Linux, Microsoft Corp., flaw, Microsoft Windows
- Discussion threads 2008-05-01
- Word up to Linux fan boys: Multiple Linux Flaws show that Linux also has kernel issues
- Not to defend Microsoft, as kernel exploits that provide privileged access are terrible flaws, but we had an interesting discussion in the talkbacks where several people acted as if Microsoft was the only place that could've made such mistakes. Well, the proof is in the pudding that this is a common flaw...
- Tags: Denial Of Service, Microsoft Word, Kernel, Debian, Flaw, Linux, Security, Operating Systems, Open Source, Software, Nathan McFeters
- Blog posts 2008-05-01
- MS08-025: Microsoft Windows kernel vulnerable to local privilege escalation Flaw
- MS08-025: Microsoft Windows kernel vulnerable to local privilege escalation flawCrumbsThe 10 year old mouse is out.Who'da thought?New news?Isn't this just rehashing news from three weeks ago? Not that it isn't a serious flaw, but it's old news. Can't we just wait for the next patch Tuesday, or is...
- Tags: Microsoft Windows Vista (Longhorn), SECURITY, Operating systems, Nothing, flaw, local access, MS08-025, Microsoft Windows, Microsoft Windows kernel, Microsoft Windows Vista, Microsoft Corp., window
- Discussion threads 2008-04-29
- MS08-025: Microsoft Windows kernel vulnerable to local privilege escalation Flaw
- From Microsoft: A local attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. This is an important security update for all supported editions of Windows 2000, Windows XP, Windows Server...
- Tags: Window, Microsoft Corp., Kernel, Flaw, Updates, Microsoft Windows, Security Administration, Operating Systems, Security, Software, Nathan McFeters
- Blog posts 2008-04-29
- HP plugs latest ActiveX software update Flaw
- HP has plugged another ActiveX vulnerability in its software update application. The patch (CVE-2008-0712) covers "a potential vulnerability has been identified with the HPeDiag ActiveX control which is a component of HP Software Update running under windows. The vulnerability could be exploited to allow remote disclosure of...
- Tags: Software, Hewlett-Packard Co., Vulnerability, ActiveX, Flaw, ActiveX/COM/COM+/DCOM, Security, Software Development, Software/Web Development, Larry Dignan
- Blog posts 2008-04-29
- More URI handler issues to come
- Rob Carter, Billy Rios, and I have been blogging about and speaking at conferences like Black Hat and ToorCon all year on the subject of URI handler abuse. One might think these types of flaws are soon to go away, but one look at SecurityFocus and FullDisclosure today and you can see...
- Tags: Flaw, Security, Nathan McFeters
- Blog posts 2008-04-25
- Adobe patches 7 issues, including Pwn2Own contest Flaw and DNS rebinding issues
- Adobe patches 7 issues, including Pwn2Own contest flaw and DNS rebinding issuesadobe was aware of pwn2own flaw since monthsadobe was aware of pwn2own flaw since months
- Tags: Domain names, flaw, Adobe patches 7, DNS Rebinding, Pwn2Own, DNS, Adobe Systems Inc.
- Discussion threads 2008-04-10
- Adobe patches 7 issues, including Pwn2Own contest Flaw and DNS rebinding issues
- Adobe published an advisory covering issues, including a fix for the Pwn2Own flaw that we previously discussed here. Adobe's details are published here. One of the issues that was patched was discovered by myself and fellow researcher (and co-worker at Ernst & Young's Advanced Security Center) Rob Carter, see the picture to the...
- Tags: Adobe Systems Inc., DNS, Domain, Lookup, Microsoft Internet Explorer, Web Browser, Domain Name, Flaw, Rob, Flash, XmlHttp Request, Kicker, Domain Names, Web Browsers, Networking, Internet, Nathan McFeters
- Blog posts 2008-04-09
- Defending Java against Paul Murphy
- Defending Java against Paul MurphyA musician's mindObviously no musician created it. But did he (or she) hang around a radio station before throwing the logic in there?Sorry Mr. Carroll...... but I'll remind you that "What moved me to respond ... was what I consider to be an inaccurate portrayal...
- Tags: Programming languages, C/C++, SECURITY, Paul Murphy, Java, flaw, C, Microsoft .NET, Microsoft Corp.
- Discussion threads 2008-04-08
- Apple patches 11 QuickTime Flaws
- Apple patches 11 QuickTime flawsGreat, means they'll beg me to download iTunes again...I only have QuickTime installed. Every QuickTime is patched, Apple Software Update (ASU) begs me to download the iTunes+QuickTime bundle, even though the first time iTunes was offered I said ignore it (via the menu) (and, I...
- Tags: Digital music, Digital media, SECURITY, Apple Inc., Apple Software, Apple QuickTime
- Discussion threads 2008-04-03
- Apple patches 11 QuickTime Flaws
- Apple pushed out the latest version of QuickTime and patched 11 vulnerabilities in its third security update of 2008. Late Wednesday, Apple pushed the update, which covers QuickTime on all platforms. The following flaws affect QuickTime on Mac OS X v10.3.9, Mac OS X v10.4.9 or later,...
- Tags: Java Applet, Apple QuickTime, Java, Movie, Apple Inc., Applet, Flaw, CVE-2008-1014, Movie File, CVE-2008-1015, Application Termination, CVE-2008-1021, CVE-2008-1022, Digital Music, Digital Media, Security, Personal Technology, Consumer Electronics, Larry Dignan
- Blog posts 2008-04-03
- Interview with the Vista Pwn2Own contest winners
- Interview with the Vista Pwn2Own contest winnersSo NO, we did not duplicate it on any other platform.What Nate states is this is a compiler issue with a polymorphism/name mangling bug. Therefore, it is not a Adobe coding issue. So my questions still remain:1) Have you duplicated this on...
- Tags: Microsoft Windows Vista (Longhorn), data execution prevention, Vista Pwn2Own, Nate, flaw, Microsoft Windows Vista
- Discussion threads 2008-04-02
- Interview with the Vista Pwn2Own contest winners
- Update 04/03/2008: I've updated the article as apparently the link to k2's blog was broken. Also, it's important to note that Derek Callaway was a part of this research and exploitation as well, and I neglected to mention that. So obviously our coverage of the Pwn2Own contest has...
- Tags: Adobe Systems Inc., Vulnerability, JavaScript, Microsoft Windows Vista, Exploit, Data Execution Prevention, Flaw, Nate, Programming Languages, Java, Security, Software Development, Software/Web Development, Nathan McFeters
- Blog posts 2008-04-02
- A minority opinion ....
- A minority opinion ....Who said Windows can't ....... run on a 64 way multi-core system without a hitch. I didn't. I merely pointed out the flaws in the author's methods. I was the one arguing that each OS has it's place. You ran off on a...
- Tags: Operating systems, .NET, OPEN SOURCE, Named Pipes, Microsoft Windows, Sun Solaris, Linux, flaw, Unix
- Discussion threads 2008-04-02
- Pwn2Own: What OS really won?
- Pwn2Own: What OS really won?They all lost!In my opinion, the Flash flaw would've been able to compromise any of the OS's, so I would say they all lost. BUT, if I had to go on who lost the most, I'd go as follows:1.) Mac OS X - A flaw...
- Tags: Operating systems, UNIX, SECURITY, operating system, Pwn2Own, flaw, Ubuntu, Linux
- Discussion threads 2008-03-31
- More details on the Pwn2Own Flash Flaw that won the Vista machine
- More details on the Pwn2Own Flash flaw that won the Vista machineOr should we blame MicrosoftFor their inability to push DEP sooner and get more of a response out developers sooner and breaking applications that have been coded wrongly for years.That would be the ABMer's excuse anyway.NBMer would say that...
- Tags: Microsoft Windows Vista (Longhorn), Programming languages, Operating systems, UNIX, SECURITY, Pwn2Own Flash, Pwn2Own Flash flaw, Microsoft Windows Vista, data execution prevention, Vista Machine, Java, flaw, Nate, Adobe Systems Inc., Microsoft Corp., Linux
- Discussion threads 2008-03-31
- More details on the Pwn2Own Flash Flaw that won the Vista machine
- So, I've been pretty surprised by the response to the discussion of the Flash flaw that allowed the Vista machine to be compromised in the Pwn2Own contest. I'm working on getting an interview with Alexander Sotirov and Shane Macaulay (see image, courtesy of ZDI's official site) to discuss the issue, but...
- Tags: Java, Microsoft Windows Vista, Data Execution Prevention, Flaw, Microsoft Windows Vista (Longhorn), Security, Operating Systems, Microsoft Windows, Software, Nathan McFeters
- Blog posts 2008-03-31
- Vista falls in Pwn2Own contests final day to a Flaw in Adobe Flash
- Update 3/29/2008: Just to clarify in case it wasn't clear, this is a flaw in an Adobe product, Adobe Flash, and not in a Microsoft product or in the Windows Vista operating system. This is important to note, as it's not quite as glamorous as the flaw that took down...
- Tags: Adobe Systems Inc., Microsoft Windows Vista, Flaw, Microsoft Windows Vista (Longhorn), Security, Operating Systems, Microsoft Windows, Software, Nathan McFeters
- Blog posts 2008-03-29
- Security: Lintel vs Wintel
- In the PC community "security" just means defending against attacks aimed at destroying or misusing all or part of a computer system. In that context most of the complexities associated with trying to decide whether wintel or lintel will expose you to less security risk arise from the absense of...
- Tags: Wintel, Attacker, Vulnerability, Flaw, National Vulnerability Database, Petreley, Security, Paul Murphy
- Blog posts 2008-03-24
White Papers and Webcasts