Anti exploit
Microsoft has indicated invents to add new anti-exploitation Apis into Windowpane Aspect SP1, Window XP SP3 and Windowpane Server 2008 as dampen of a larger design to inviolable the Windowpane ecosystem.
According to Michael Howard, a elderly circularise manager in Microsoft's surety unit, the work of the new NX (/noexecute) Apis significantly lowers the barriers to launching for finish developers to opt-in to victimization DEP on Window programs.
In his announcement, Howard said the new Apis forget let developers set DEP on their member at runtime rather than victimization linker options.
The key API beingness binded is Setprocessdeppolicy, which solids the DEP advancement for the form process, he said.
[ SEE: Microsoft Claims Warrantor Win with New Develop Rules ]
Howard said there are troika briny objects to use the new Windowpane Apis:
* If your finishing has some flesh of in-process extensibility mechanism, and some applications mightiness use aged ATL, later you can enable DEP for your process, and the extensibility mechanisms exploitation ATL depart thing correctly.* If you concomitant DEP but deprivation to bequeath deal to handicap DEP if there are required rapport issues, thereupon that is the API to use for the debate can be a conformation option.
* If your finish uses an old adaptation of ATL, and you distillery deprivation to do the right-hand intimacy by DEP, next use that function. Of course, you truly pauperism to use an updated adaptation of ATL!
And from my co-worker Larry Seltzer.
Create, Communicate, Collaborate with IT Professionals at Ziff Davys Attempt IT Connection
Posted by Ryan Naraine on Jan 30, 2008 2:01 PM
Permalink | Comments (1) | del.icio.us | digg.com | Trackback | Berth a Annotating Scene all of Exploits and Attacks, Encroachment Detection/prevention, Microsoft Windows, Exposure Enquiry
Trackback http://securitywatch.eweek.com/c
gi-bin/mte/mt-tb.cgi/12597 Listed below are hyperlinks to weblogs this credit Microsoft Adds New Anti-exploit Apis into Windows:
Microsoft Adds New Anti-exploit Apis into Windowpane from Microsoft Schweiz Warrantor Blog Microsoft has argued begets to add new anti-exploitation Apis into Window Aspect SP1, Window XP SP3 [read More] Tracked on Feb 4, 2008 7:30 AM Comments (1) Kostya Kortchinsky :It shows to me as the substantially estimate Microsoft power etymologizing up with to conveniences ret2libc-style attacks in DEP good applications. Present you get to string 3+ calls to do that, again that boasting is available, it allow be 1 (2 at most).
Related sites:
Anti DSO exploit Screenshots
What do gun shows have to do with the September 11 attack on the World Trade Center? Answer: Nothing, but that doesn't stop the gun grabbers from trying to exploit ... ...
Protect yourself from rootkits and zero-day exploits ... Zero-day exploits. Zero-day exploits are released on the same day the vulnerability - and, sometimes, the vendor patch ...
New York, NY, January 4, 2007 … Jimmy Carter's efforts to promote his book ... Press Release: Israel: Anti-Semites, White Supremacists Exploit Jimmy Carter's Book for Propaganda ...
ConfigServer Services cPanel Server Services from Way to The Web Ltd ...
LinuxSecurity.co m delivers the latest breaking news and information on security, linux, open source, firewalls, networks, privacy, encryption, cryptography, hacks, attacks ...
Microsoft has announced plans to add new anti-exploitatio n APIs into Windows Vista SP1, Windows XP SP3 and Windows Server 2008 as part of a larger plan to secure the Windows ...
Hi folks, This has been an exceptionally busy month for us - fortunately not because of any specific new bad-guy activity. But we're making sure we're as ready as we can be for the ...
NRA-ILA FAX ALERT (800) 392-8683: Fax: (703) 267-3918: groots@nra.org: Vol. 8, No. 39: 11250 Waples Mill Road, Fairfax, VA 22030: 9/28/2001
<< Home