Tutorial

Go Back   Tutorial > Technology > Home security tips

Forum overview

Latest topics
Show:

Portalsearch

Advanced Search

Statistic
Topics: 34936
We welcome our newest user: VomaHeeseex
New users:
11-22-2008
- VomaHeeseex
11-22-2008
- ToomiFearma
11-22-2008
- Greevedic
11-22-2008
- OnesStelsnemi
11-21-2008
- Hauhpaimupt


Example of Security Product Introducing Vulnerabilities


Home security tips

Sponsored Links:

Reply
 
Thread Tools Search this Thread Display Modes

  #1  
Old 09-11-2007, 07:26 PM
LapTop's Avatar
LapTop LapTop is offline
Administrator
 
Join Date: Apr 2007
Posts: 21,889
Example of Security Product Introducing Vulnerabilities

Sponsored Links:
One of the reasons I blog is to record concrete events so I can more easily reference the exact details in the future. In Black Hat USA 2007 Round Up Part 2 I said:

Modern countermeasures applied to reduce vulnerability and/or exposure in many cases increase both vulnerability and exposure. This is certainly the case with so many agents (see Matasano is Right About Agents.)

Sometimes these vulnerabilities are present in the agent itself, such that the agent can be directly attacked. In other cases (like the one I cite today), the agent appears to re-introduce a vulnerability that the underlying system fixed years ago. From Haxdoors of the Kaspersky Antivirus 6/7:

Kaspesky [sic] and System Service Descriptor Table

Very long time is known that this is the weakest part of this antivirus. The weakest, because it contains number of elementary bugs.

Another example of poorly coded so-called Proactive Defense. On Windows XP Kaspersky AV adds additional services in SSDT table...

And now surprise. Any of this unknown SSDT entries can be EXPLOITED and can crash system into the BSOD even from Guest account with MINIMAL PRIVILEGES. We coded simple program. Its generates invalid system calls with invalid parameters for these unknown SSDT entries. The code is very simple but efficient. Using the same on clean Windows will lead to nothing, because Windows handles such situation in the right manner.
(emphasis added)

Please excuse the English; the speaker is Russian. (How is your Russian?)

In other words, normal Windows without Kaspersky is immune. Windows plus Kaspersky (supposedly equalling "defense in depth") is vulnerable.

Please remember this whenever you write (horror) or read a policy that requires anti-virus on all systems, regardless of the cost-benefit equation.Copyright 2003-2007 Richard Bejtlich
Sponsored Links:
Reply With Quote
  #2  
Old 09-11-2007, 10:13 PM
LapTop's Avatar
LapTop LapTop is offline
Administrator
 
Join Date: Apr 2007
Posts: 21,889
Sponsored Links:
6- Download software, Free software download, free software, free download, software download
7- Beauty girl, Girl beauty, picture beauty girls, bikini girl, blog girl
8- Gphone google, Google gphone, Google Phone Review, Google Phone Support, Google Phone Tools, Google Phone news, Gphone, google mobile
9- Make money, stock market, Make money online, online money, make easy money
Sponsored Links:
Reply With Quote
Reply

Sponsored Links:

Compare price

Compare products

Download software


Free Download Softwware


Tags: , , , ,



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Health Product From Dead Sea LapTop Xp tips 0 08-28-2007 01:01 PM
Cerulean Studios Trillian Multiple IRC Vulnerabilities LapTop Home security tips 0 05-02-2007 12:13 AM
Way to get xp product code from cd, It really work LapTop Xp tips 0 04-29-2007 12:51 AM
Product Reviews: Crankbaits LapTop Fishing tips 0 04-28-2007 11:22 AM



All times are GMT. The time now is 11:48 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

RSS 2.0 HOME