The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Apple and Microsoft get trashed by hackers again
Time: 13:51 EST/18:51 GMT | News Source: the inquirer | Posted By: Andi Stabryla

DESPITE THE RABID CLAIMS of Apple fan boys that its software is more secure than anything else on the market, Jobs' Mob products were the first to be trashed again at a Pwn2Own hacking competition.

Write Comment
Return to News

  Displaying 1 through 25 of 334
Last | Next
  The time now is 8:07:22 AM ET.
Any comment problems? E-mail us
#1 By 23275 (68.117.163.128) at 3/25/2010 2:12:53 PM
Google's Chrome was not tested (again this year)

First, Google's Chrome browser only uses the EXACT SAME Microsoft technologies it is inappropriately credited for innovating, that were first used in IE 7 on Windows Vista - namely "Secureable Objects" and the UIPI (a brokering agent), which prevents escalations outside of the highly restricted space IE 7/8 operate in (named space with lover permissions than even standard user space, which is the default for ALL Windows Vista and 7 IE users). Google has been very candid about the fact that they did nothing unique to "Sandbox" Chrome and that they only used techniques provided by Microsoft and freely available to all developers and software written for Windows Vista and 7. By the way, these are only two techniques available within the Windows Integrity Mechanism. IE 7/8 on Vista and 7 brand these as "Protected Mode" - the default configuration.

Second, Windows Vista and 7 x64 (now very common) use hardware NX, or zero execute, which is the default on main boards and has been since 2005. This is hardware based DEP.

Third, software DEP is enabled by default in Windows Vista/7 x64, but alone is not enough - so Windows Vista and 7 x64 add Automated Space Layout Randomization (ASLR) by default. The combination of NX (hardware DEP) Software DEP and ASLR layered in and behind Secureable Objects, the UIPI and opposite Standard Users (for ALL users (system/root admin accounts are disabled by default in Vista/7 - leaving "Admin Approval Mode" users, or standards users)).

Fourth, IE 8 adds the SmartScreen filter, which dynamically updates and filters all web traffic - it has been proven to be the most effective filter of its kind.

Fifth, Windows Vista/7 x64 based systems add even more layers of security via the Window Filtering Platform (WPF) and File System Filters (FSF), which are specifically designed to integrate to the FREE Microsoft Security Essentials, previously marketed Windows Live OneCare and all commercial Microsoft Sterling/Forefront Client Security suites. These added filters work cooperatively with these security suites.

Now... beyond all of this, Windows Vista and 7 feature User Account Control (UAC), which should be set at its highest level in 7 and left enabled on Vista. Vista/7 also allow one to run as a standard user, vice an Admin Approval Mode user (where one enters actual passwords for such things as installing software - vice clicking a button in admin approval mode). Given all these security features, which entirely mitigate this exploit, Internet Explorer 8 on Windows Vista/7 x64 are THE MOST SECURE browsing experience one may have and still enjoy the web. If that is not enough, the special NO-FLASH version of IE x64 on Vista/7 x64 may be used and the only plug-in that by design, bypasses IE's/Google Chrome's "sandbox" Protected Mode (Adobe FLASH) may be easily started and run.

Please forget the hype and Bovine Scatology you read here and in our press - it is all just that, pure BS. Run as I have shown above and ignore the cruft that passes for advice, junk computer science and forum nonsense.



This post was edited by lketchum on Thursday, March 25, 2010 at 14:38.

#2 By 23275 (68.117.163.128) at 3/25/2010 2:52:04 PM
The below is posted so that people understand that the same vulns/exploits that work for IE 8 also work on Google's Chrome.

Google's Chrome was not tested (again this year)

Google's Chrome browser only uses the EXACT SAME Microsoft technologies

Unlike IE 7/8, Google's Chrome browser does not broker the plug-in, like MS/IE does for its add-ons!

From Google: "The operating system might have bugs. Of interest are bugs in the Windows API that allow the bypass of the regular security checks. If such a bug exists, malware will be able to bypass the sandbox restrictions and broker policy and possibly compromise the computer. Under Windows, there is no practical way to prevent code in the sandbox from calling a system service.

In addition, third party software, particularly anti-malware solutions, can create new attack vectors. The most troublesome are applications that inject dlls in order to enable some (usually unwanted) capability. These dlls will also get injected in the sandbox process. In the best case they will malfunction, and in the worst case can create backdoors to other processes or to the file system itself, enabling specially crafted malware to escape the sandbox."
REF: http://dev.chromium.org/developers/design-documents/sandbox#TOC-Other-caveats

#3 By 23275 (68.117.163.128) at 3/25/2010 2:54:09 PM
Ref my #2, above and emphasis on where they say: "no pratical way..."

Microsoft has found such a practical way - to broker all processes except: Adobe Flash!

To remain entirely safe, run the included x64 version of IE 8 on Windows 7

#4 By 12071 (203.210.68.145) at 3/25/2010 6:17:43 PM
#1 "Google's Chrome was not tested (again this year)"
Seriously, get a box of tissues and just let it all out. Just because they went for the easy targets first... including taking down IE8 on 64bit Windows 7.

http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009
"The browser targets will be IE8, Firefox, and Chrome installed on a Sony Vaio running Windows 7 as well as Safari and Firefox installed on a Macbook running Mac OS X."

http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010
"The browser targets this year will include the latest versions of Microsoft Internet Explorer, Mozilla Firefox, Google Chrome and Apple Safari."

"To remain entirely safe, run the included x64 version of IE 8 on Windows 7"
Ha!! http://vreugdenhilresearch.nl/Pwn2Own-2010-Windows7-InternetExplorer8.pdf. Perhaps it's time to take your own advice: "Please forget the hype and Bovine Scatology you read here". You really should go work for Microsoft - you can be their version of the Iraqi Information Minister.

#5 By 23275 (68.117.163.128) at 3/25/2010 7:37:26 PM
#4, Have you read that the exploits relied upon a "information disclosure" to get at IE 8?
e.g., a shared source disclosure? So the researcher would know exactly to where they were writing. Also, it has not been disclosed the the IE 8 version exploited was the x64 version - ONLY that the x64 version of Windows 7 was. It was likely the 32 bit version of IE 8 on x64 Windows.

Also, it is nonsense that you say Chrome was not tested as it is harder. It was not tested at all and that was disclosed AFTER the event. Just as last year, it will come out that the same exploits would have worked on Google Chrome - since Google uses Microsoft's security technologies and finally, it was a default Windows 7 x64 install, so UAC would have been set at a lower level and more processes would be trusted than I have recommended and the default user would have been an admin approval mode user - also against what I have recommended.

#6 By 143 (216.205.223.146) at 3/25/2010 8:13:11 PM
Religious warfare is so wrong.

#7 By 11888 (173.35.101.9) at 3/25/2010 9:16:03 PM
Charlie Miller himself says that he doesn't know how to exploit Chrome to accomplish anything. Why bother if no one has a clue how to do it?

#4, Iraqi Information Minister! Hilarious!

#8 By 11888 (173.35.101.9) at 3/25/2010 9:16:42 PM
I get a kick of this place. It's like a tech parody site. No credible information at all.

#9 By 17855 (205.167.180.132) at 3/26/2010 8:19:23 AM
#1 All excellent points. However average Joe PCUser doesn't care, nor does the bloggy world. Only some people can truly see through the hype of these kind of events.

What I would like to see is a contest pitting IT administrators against each other, just to see who has the strongest security configurations. What works and what works better. Now theres an article.

#10 By 23275 (68.117.163.128) at 3/26/2010 10:28:16 AM
#7, #8, Really?

SetProcessDEPPolicy is supported for 32-bit processes only. If this function is called on a 64-bit process, it fails with STATUS_NOT_SUPPORTED

As I said, run IE 8 x64 (unless you just have to have FLASH) and ignore this exploit, which was greatly aided by the aforementioned "information disclosure" As stressed, also elevate Windows 7 UAC to its highest setting as is the default on Windows Vista and run as a standard user at all times. ***If you need to install a new driver - say a GPU driver update, log off and log back in as an Admin Approval Mode user you use to do very specific things***

#11 By 1896 (68.153.171.248) at 3/26/2010 1:06:34 PM
What is the default browser in W7 64 bit? Correct me if I was wrong but in all my ststem is IE 32 and not 64.

What is the reasoning behind MS choice to use IE32 in a 64 OS? My guess is a higher degree of compatibility but I am not an expert in this matter.

Anyway a test is, or at least should be, run using a standard/default installation of the components.

Said that I use IE 64 and UAC at the highest level but..... as everybody else here I am not representative of what is considered "the average user".

#12 By 15406 (216.191.227.68) at 3/26/2010 2:46:30 PM
I love this time of year. Spring is almost upon us, the snow is melting, Pwn2Own is happening and Ketchum is writhing in agony as his pro-MS, pro-IE recommendations get shredded. Then it gets funnier as you watch him furiously spinning and babbling to somehow reconcile reality with the sunshine-and-rainbows MS narrative he forever paints. Let me guess the next recommendation:

"The most secure browsing experience can only be had with IE9 Beta, x64, with DEP, NX, ASLR, ABC, EFG and LMNOP."

Priceless.

#13 By 28801 (68.82.112.163) at 3/26/2010 4:02:22 PM
#12: No!!!

FF with NOSCRIPT, FLASHBLOCKER, ANTIBROWSE, and diagnal tabs is definately the way to go.

#14 By 23275 (68.117.163.128) at 3/27/2010 10:11:11 AM
Latch, are you that simple? Really?

These events are really useful, but they get distorted and they are reported as perversions of the truth and that masks their value. It's very unfortunate, because one is left to present the practical considerations attending the reporting that comes out of them.

The reality is that we're reading about tiny portions of a series of experiements and the conditions are never disclosed in detail. The conditions of the experiments matter and there is great good that is derived from them.

Yet, guys like you don't even consider that perspective - no more than the lay press does.

#15 By 4240821 (213.139.195.162) at 10/27/2023 9:15:27 AM
https://sexonly.top/get/b545/b545omosffclqjzklhp.php
https://sexonly.top/get/b24/b24niklhnkcnrlcfkh.php
https://sexonly.top/get/b92/b92etkxexdblljqnzo.php
https://sexonly.top/get/b719/b719reibvdzcwdivjzb.php
https://sexonly.top/get/b848/b848zcwwigarasdorar.php
https://sexonly.top/get/b301/b301fkjgzshmotswvgl.php
https://sexonly.top/get/b335/b335fmdjndmxathuoox.php
https://sexonly.top/get/b579/b579wilhuayupqlzfww.php
https://sexonly.top/get/b448/b448fshwxqxktessftz.php
https://sexonly.top/get/b34/b34ehizhkzvebidbir.php
https://sexonly.top/get/b241/b241utortqspnpriofd.php
https://sexonly.top/get/b345/b345nttidarxfeiofhp.php
https://sexonly.top/get/b513/b513etxtvofkrteaerg.php
https://sexonly.top/get/b953/b953uheltklvhdiemfp.php
https://sexonly.top/get/b451/b451etlzgmszfmztrxs.php
https://sexonly.top/get/b677/b677dhlkrnzhvqvlpvg.php
https://sexonly.top/get/b900/b900wksowsabmskwbea.php
https://sexonly.top/get/b796/b796mdwdzzkhidzlpoe.php
https://sexonly.top/get/b430/b430cuvqucjhmtpxfpn.php
https://sexonly.top/get/b317/b317wqnhodfxwuawdvc.php
https://sexonly.top/get/b683/b683vjymesxidtivisd.php
https://sexonly.top/get/b175/b175hmbgagcrvnmcnoa.php
https://sexonly.top/get/b710/b710omnokxsxitlembm.php
https://sexonly.top/get/b53/b53eehnhuxigtyiauz.php
https://sexonly.top/get/b157/b157zfyzuzdqtmxfjcj.php
https://sexonly.top/get/b433/b433huaifqgkozjbwpp.php
https://sexonly.top/get/b812/b812ebzugannuqstocv.php
https://sexonly.top/get/b48/b48omxgdekklqnjatx.php
https://sexonly.top/get/b977/b977pjkeghrupexgvdb.php
https://sexonly.top/get/b153/b153ipmkvkxpwcbobcg.php
https://sexonly.top/get/b789/b789vusndngtauadfjr.php
https://sexonly.top/get/b404/b404wkbyyhdqmamhlnm.php
https://sexonly.top/get/b207/b207oymwfnirinohdra.php
https://sexonly.top/get/b234/b234wuzsvyvyorgkuxp.php
https://sexonly.top/get/b283/b283afwzdziqxhpywvw.php
https://sexonly.top/get/b978/b978kveeoauixvjjevv.php
https://sexonly.top/get/b790/b790mhbuycnfwhlxgpz.php
https://sexonly.top/get/b212/b212fxbwvymgznhlpxm.php
https://sexonly.top/get/b627/b627fhbiuyfsahshjtp.php
https://sexonly.top/get/b289/b289ptshbdetusvgptv.php
https://sexonly.top/get/b165/b165btmkcpaknlvfnet.php
https://sexonly.top/get/b808/b808omyeezyqtxxarxi.php
https://sexonly.top/get/b125/b125aegkarbvpjqwyvl.php
https://sexonly.top/get/b278/b278ysoapsrrpacujcd.php
https://sexonly.top/get/b435/b435uhofezyruozxlbz.php
https://sexonly.top/get/b720/b720jkleqfyfjxdgndj.php
https://sexonly.top/get/b104/b104azubqpfnahlmywu.php
https://sexonly.top/get/b339/b339kifqccvzoagqxjt.php
https://sexonly.top/get/b74/b74boredudxqnoxyzf.php
https://sexonly.top/get/b247/b247dhagwuvwqvwsjhg.php

#16 By 4240821 (103.151.103.150) at 10/30/2023 5:35:22 PM
https://www.quora.com/profile/AnnieSchneider430/Luna-Villa-emmyamelia_xx-Beautii212-Misty_Phoenix-Hornygermans-white_mexican-twicexxbitten-VictoriaVega
https://www.quora.com/profile/ChadBlodgett85/xviip3rxx-big_ass_sandy1-MissEllyy-luna-show-AlexaWhittee-AlexaFoxy-sarahjessiexxx-Emily-Cole-Jasmine-Mo
https://www.quora.com/profile/JessicaKing51/lalla_potira-Miss-Squirtsalot-dirtykittykink-Sassy-Slutt-SC3-kittenslave-DeVinityFinesseXXX-Mistydark-jani
https://www.quora.com/profile/TanyaStevenson1/mistress_zabava-katASShley-Lady-Loyalty-Crystal-Carter-Brittany-Oconnell-zoefelicitas99-ladymaya-1-Dakotah
https://www.quora.com/profile/CharlesCashion274/bambiblacks-Freerangeamber-Kacie-Castle-fitnessbarbie26-Xxxelda-LeilaGreen-alana_mcl-anabell-bella-Jasmi
https://www.quora.com/profile/TimothyRocker460/wefuck2good-Joey-Green-katiiidel-BushyBabe1-Kenzibebe-OFFICIALNIKKYDUNES-MrsPink-Hayley_x_x-MochaBunnyxx
https://www.quora.com/profile/AatiyahKatarezzy75/Eveslovesalot-blakiebabie1-Laylahh-Harley-Blazed-Brat-melimelidc-Robbie69Roxxxi-Tchabada-Babyygoree97-Mi
https://www.quora.com/profile/RobertDarling143/chelsea-charms-MIssygirl910-afton-marie-DeLuxious-Kittyboomboom-Angel-Baby-PhoenixRiver-SadodereBDSM-Mis
https://www.quora.com/profile/DanielleJohnson912/reneepaige696-Sawyer-Sloane-KirstyMxoxo-Stormi-Fantasia-makoto-toda-awesome1982-Basicbossmomma-Juicypussyh
https://www.quora.com/profile/DanielleThomas718/MissMedusa115-cristia2016-Natalie-K-Fantasticastetas-AmputeeKarolina-necilarrozz9192-Kenna26-Annahotbabie

#17 By 4240821 (103.152.17.80) at 10/31/2023 6:17:08 AM
https://app.socie.com.br/read-blog/97512
https://app.socie.com.br/read-blog/97430
https://app.socie.com.br/read-blog/97570
https://app.socie.com.br/read-blog/98248
https://app.socie.com.br/read-blog/97176
https://app.socie.com.br/MikuOhashiAmberSunshine
https://app.socie.com.br/MyStickySweetFeetProbUrFave
https://app.socie.com.br/read-blog/97489
https://app.socie.com.br/read-blog/97589
https://app.socie.com.br/read-blog/97488

#18 By 4240821 (103.151.103.150) at 10/31/2023 5:25:13 PM
https://app.socie.com.br/read-blog/97667
https://app.socie.com.br/read-blog/97641
https://app.socie.com.br/read-blog/97570
https://app.socie.com.br/read-blog/97499
https://app.socie.com.br/xxxaylazaneKittyRains
https://app.socie.com.br/AGJGD69Ange_M
https://app.socie.com.br/read-blog/97465
https://app.socie.com.br/AktatatataCendal
https://app.socie.com.br/read-blog/97272
https://app.socie.com.br/read-blog/98831

#19 By 4240821 (62.76.146.75) at 11/1/2023 9:05:07 AM
http://activewin.com/mac/comments.asp?ThreadIndex=67608&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=33796&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=9151&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=73296&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=72737&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=23761&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=68423&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=25631&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85121&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=15502&Group=Last

#20 By 4240821 (109.94.218.82) at 11/2/2023 4:35:53 PM
http://activewin.com/mac/comments.asp?ThreadIndex=24532&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=22923&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=18678&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=63525&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=56898&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85380&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=25775&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=27903&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=55235&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85060&Group=Last

#21 By 4240821 (212.193.138.10) at 11/3/2023 6:16:56 PM
http://activewin.com/mac/comments.asp?ThreadIndex=24975&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=80519&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=72612&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=68662&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=8412&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=7056&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=12368&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=60087&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=84272&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74658&Group=Last

#22 By 4240821 (109.94.216.41) at 11/4/2023 7:49:11 PM
https://hotslutss.bdsmlr.com/post/653847274
https://hotslutss.bdsmlr.com/post/662772264
https://hotslutss.bdsmlr.com/post/655994061
https://hotslutss.bdsmlr.com/post/658583042
https://hotslutss.bdsmlr.com/post/652135738
https://hotslutss.bdsmlr.com/post/658053855
https://hotslutss.bdsmlr.com/post/649108685
https://hotslutss.bdsmlr.com/post/650063490
https://hotslutss.bdsmlr.com/post/661412505
https://hotslutss.bdsmlr.com/post/650975323

#23 By 4240821 (92.119.163.194) at 11/6/2023 10:35:47 AM
https://printable-calendar.mn.co/members/19903556
https://printable-calendar.mn.co/members/19909957
https://printable-calendar.mn.co/members/19901204
https://printable-calendar.mn.co/members/19894890
https://printable-calendar.mn.co/members/19910326
https://printable-calendar.mn.co/members/19897893
https://printable-calendar.mn.co/members/19915467
https://printable-calendar.mn.co/members/19914922
https://printable-calendar.mn.co/members/19910738
https://printable-calendar.mn.co/members/19900581

#24 By 4240821 (62.76.146.75) at 11/8/2023 6:34:48 AM
https://www.hackerearth.com/@seoudusiging1981
https://www.hackerearth.com/@huytisubsnull1982
https://www.hackerearth.com/@inexapin1970
https://www.hackerearth.com/@gravnitipa1977
https://www.hackerearth.com/@tomrandberdodd1984
https://www.hackerearth.com/@lighbhajreza1978
https://www.hackerearth.com/@vebevilri1977
https://www.hackerearth.com/@plesacveso1977
https://www.hackerearth.com/@orfladviti1989
https://www.hackerearth.com/@gregennowcei1977

#25 By 4240821 (45.146.26.215) at 11/10/2023 6:13:07 PM
http://www.ttbizonline.com/pro/20231109135057
http://www.ttbizonline.com/pro/20231109195157
http://www.ttbizonline.com/pro/20231109085831
http://www.ttbizonline.com/pro/20231109123336
http://www.ttbizonline.com/pro/20231109180813
http://www.ttbizonline.com/pro/20231110030551
http://www.ttbizonline.com/pro/20231109193050
http://www.ttbizonline.com/pro/20231109200602
http://www.ttbizonline.com/pro/20231110025216
http://www.ttbizonline.com/pro/20231109194446

Write Comment
Return to News
  Displaying 1 through 25 of 334
Last | Next
  The time now is 8:07:22 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *