internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Ad-Aware 2008 Free
Internet Explorer 7
QuickTime for Windows
Paint Shop Pro
Mozilla Firefox Portable Edition 3
AVG Anti-Virus Free
Windows XP Service Pack 3
Ashampoo WinOptimizer
Adobe Flash Player
Windows Live Suite

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Windows XP SP2 Said at Risk From Heap Overflow
New Security Flaw Identified in XP SP2
Sean Michael Kerner

Microsoft said it is is investigating a report from Alexander Anisimov of the Russian security firm Positive Technologies that details how to bypass Windows XP SP2 heap protection to create an attack vector for a buffer overflow attack.

According to Positive Technologies' security scanning product MaxPatrol, it initially notified Microsoft of the bypass on Dec. 21, 2004, and sent proof of concept code to them on Dec. 22nd. MaxPatrol also indicated that Microsoft provided an initial response on the same day, though at this point it does not appear as though a fix or patch has been issued.

The exploitation of buffer overflows/overruns are a common approach vector for malicious users to gain control of a user's PC. A spokesperson for Microsoft noted that heap overflow technology was never meant to be foolproof.

According to Positive Technologies, the effect of a successful attack utilizing the detailed method they explain is that an attacker will be able to execute arbitrary code, including arbitrary memory region write access. The attack with also effectively bypass Microsoft's Data Execution Prevention (DEP) measures, which could leave a PC wide open to further infiltration and damage.

Windows XP SP2 contains a pair of mechanisms that is supposed to prevent and/or limit buffer overflows, NX protection for 64-bit processors (which is a chip-level "No Execute" flag) and something called Sandboxing, which was added in SP2 for 32-bit processors.

Sandboxing protects the stack (define) and the heap (define) memory storage types. The Russian Security firm's method for creating a buffer overflow bypasses the Sandbox.

According to an e-mail statement from a Microsoft representative, the company's early analysis indicates that this attempt to bypass these features is not a security vulnerability. An attacker cannot use this method by itself to attempt to run malicious code on a user's system. There is no attack that utilizes this, and customers are not at risk from the situation in Microsoft's opinion.

However, Microsoft isn't saying that SP2's method for preventing a buffer overflow will prevent all such attacks.

"It's important to note that data execution protection and heap overflow protection were never meant to be foolproof; the purpose of these features is to make it more difficult for an attacker to run malicious software on the computer as the result of a buffer overrun," the Microsoft e-mail states.

"We will continue to modify these technologies as appropriate to improve them and will evaluate ways to mitigate against this method of bypass while retaining performance on the system, either through an update as part of our monthly bulletin release process, or in a future service pack."

News courtesy of internetnews.com

January 31, 2005


Download Windows XP Service Pack 2 Now!Download

View All Service Packs

Contents:
1. New Security Flaw Identified in XP SP2


Additional Articles:

  • Windows XP Service Packs: What's New in XP SP2
  • Windows XP SP2 Inches Closer
  • XP SP2 Launch Price: $300 Million
  • XP SP2: Do's & Don'ts for Web Sites
  • Windows XP SP2 Comes Closer with RC2
  • August It Is for XP SP2
  • Microsoft's XP SP2 Arrives
  • Microsoft XP SP2 Blog Watch
  • XP SP2 Warning List Released
  • XP SP2 Delivery Schedule Adjusted
  • Researcher Finds Flaws in XP SP2
  • MS Releases XP SP2 App Testing Guide
  • XP SP2 Deadline Extended
  • Microsoft Releases Scanning Tool
  • XP SP2 Downloads Surpass 100M Mark
  • Enterprise Foot-Dragging on XP SP2
  • Do You SP2?
  • Windows XP Service Pack 3 Pushed Back to 2008
  • Would You Like 'XP' With That PC?
  • Vista, XP Service Pack Changes Revealed
  • Public Test for XP Service Pack 3
  • Windows XP Service Pack 3? Place Your Bets
  • Microsoft: XP Not Out to Pasture Yet
  • Get the Latest on Windows XP SP3
  • Windows XP SP3 Just Around The Corner
  • When Is a Downgrade a Good Thing?
  • No XP Service Pack 3 for You Today
  • On Again, Off Again, XP SP3 Back On
  • XP SP3 Glitch a 'Gotcha' for IE7 & IE8
  • Microsoft Just Can't Kill XP
  • Meet Microsoft's New Embedded OS: Windows XP




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    IBM eBook: Planning a Service Oriented Architecture
    IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
    Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
    Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
    Intel Go Parallel Article: Getting Started with TBB on Windows
    Microsoft Article: 7.0, Microsoft's Lucky Version?
    Avaya Article: How to Feed Data into the Avaya Event Processor
    IBM Article: Developing a Software Policy for Your Organization
    Microsoft Article: Managing Virtual Machines with Microsoft System Center
    Intel Go Parallel Article: Intel Threading Tools and OpenMP
    HP eBook: Storage Networking , Part 1
    Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    HP Video: StorageWorks EVA4400 and Oracle
    HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
    Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
    Iron Speed Designer Application Generator
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
    IBM Article: Enterprise Search--Do You Know What's Out There?
    HP Demo: StorageWorks EVA4400
    Microsoft Article: The Progress and Promise of Deep Zoom
    Microsoft How-to Article: Get Going with Silverlight and Windows Live
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES