Apolyton Archive  |  Preserved copy of the Apolyton Civilization Site and its forums as they stood in September 2005. Read-only; nothing here can be posted to or replied to.  |  Forum index |  About this archive |  The 1998–2001 UBB forums
Today on Apolyton WARDELL INTERVIEW PROMO A.C.S. HISTORY CHAPTER 4 GET CIV4 /w FREE PLUS! A.C.S. PHOTO GALLERY GET A.O.M. V1.1
Apolyton Civilization Forums
main| civ2| civ3| civ4| smac| ctp2| ron| moo3| galciv| galciv2| alt| about|
ApolytonPLUS | register | search | faq | new posts | pm (-/-) | upload | members
hall of fame new! | civgroups | civgroups news | interviews | the column | radio | chat | directory | news | store | PLUS
Apolyton Civilization Forums : Powered by vBulletin version 2.0.3 Apolyton Civilization Forums > Miscellaneous > Off-Topic > Windows XP SP2 breached
Show a Printable Version | Email This Page to Someone! | Receive updates to this thread | Report this to Apolyton news!
20.Sep: FOURTH CHAPTER IN `HISTORY OF...` PUBLISHED
13.Sep: NEWS ON THE FLY
06.Sep: APOLYTON DONATES TO HURRICANE RELIEF

bottom of page
   - CIVILIZATION 3 $9.99 - CIVILIZATION 2 from $6.95 - CIVILIZATION 2 from $4.25 - ALPHA CENTAURI + ALIEN CROSSFIRE (laptop collection) from $19.99 - ALPHA CENTAURI PC $9.99 -->
Author
Thread    < Last Thread     Next Thread > Post New Thread     Post A Reply
Urban Ranger is offline Urban Ranger
Apolyton Duke of Off-Topic

Donate to the Red Cross
The City State of Noosphere, CPA special envoy
May 1999
time: 13:29
  Old Post 31-01-2005 13:52
Edit/Delete Message Reply w/Quote
#1 Report this post to a moderator
Windows XP SP2 breached Tired of ads?

Blurb:

quote:

In October 2004 it was discovered by MaxPatrol team that it is possible to defeat Microsoft® Windows® XP SP2 Heap protection and Data Execution Prevention mechanism. As a result it is possible to implement:
  1. Arbitrary memory region write access (smaller or equal to 1016 bytes)
  2. Arbitrary code execution
  3. DEP bypass.


Big ouch. Big big ouch. Back to the drawing board.

Agathon is offline Agathon
Prince
Leafs 4TW!! - CPA
Dec 2002
time: 00:29
  Old Post 31-01-2005 17:46
Edit/Delete Message Reply w/Quote
#2 Report this post to a moderator
Enter the AD-FREE zone

What? Again?

Windows XP is like that ugly girl at the pub which everyone's nailed.

Imran Siddiqui is offline Imran Siddiqui

Deity
The Potterverse
Jan 1970
time: 00:29
  Old Post 31-01-2005 18:59
Edit/Delete Message Reply w/Quote
#3 Report this post to a moderator
Support Apolyton, buy GURPS/ Alpha Centauri

Actually it'd be the super-hot girl, because everyone is gunning for her.

Cruddy is offline Cruddy
Warlord

Mar 2003
time: 05:29
  Old Post 31-01-2005 19:28 Visit Cruddy's homepage!
Edit/Delete Message Reply w/Quote
#4 Report this post to a moderator
Support Apolyton, buy Galactic Civilizations: Deluxe Edition

quote:
Originally posted by Agathon
What? Again?

Windows XP is like that ugly girl at the pub which everyone's nailed.


The rest of the world calls them sheep, Agathon.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 31-01-2005 19:38 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#5 Report this post to a moderator
Enter the AD-FREE zone

Actually, only the stack protection has been "breached", and only on systems without NX/XD instructions (Athlon 64s, new Pentium 4s). NX/XD-supporting systems stop these cold.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 31-01-2005 19:42 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#6 Report this post to a moderator
Support Apolyton, buy Civilization: The Boardgame

Since I'm not entirely confident you even know what NX/XD is, here's that site's blurb:
quote:
On the 64-bit AMD K8 and Intel Itanium processor families, the CPU hardware can mark memory with an attribute that indicates that code should not be executed from that memory. This execution protection (NX) feature functions on a per-virtual memory page basis, most often changing a bit in the page table entry to mark the memory page.



On these processors, Windows XP Service Pack 2 uses the execution protection feature to prevent the execution of code from data pages. When an attempt is made to run code from a marked data page, the processor hardware raises an exception immediately and prevents the code from executing. This prevents attackers from overrunning a data buffer with code and then executing the code; it would have stopped the Blaster worm dead in its tracks.

Although the support for this feature is currently limited to 64-bit processors, Microsoft expects future 32-bit and 64-bit processors to provide execution protection.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 31-01-2005 20:42 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#7 Report this post to a moderator
Support Apolyton, buy Civilization III: Complete

Boo, where'd everyone go?

Having read the entire PDF now (I'm at work and bored), I have to wonder if anyone else who is making claims like "SP2 Breached" actually read it.

In addition to only affecting systems without NX/XD support ("software" DEP/"sandboxing" instead of "hardware"), it'll also require an exploitable memory error in a system component (there are none known right now) that uses a very specific method of heap allocation, including using heap lookaside lists (which are disabled by default).

In short, . The chances of this being an issue are slim to none, and it's more FUD from the people who claim to hate FUD.

You'd think the Linux geeks who keep buzzing about this would best spend their time upgrading their linux boxes.

There were 17 Linux kernel vulnerabilities recently...
http://www.securityfocus.org/bid/11491
http://www.securityfocus.org/bid/11492
http://www.securityfocus.org/bid/11533
http://www.securityfocus.org/bid/11488
http://www.securityfocus.org/bid/11695
http://www.securityfocus.org/bid/11921
http://www.securityfocus.org/bid/11937
http://www.securityfocus.org/bid/11715
http://www.securityfocus.org/bid/11939
http://www.securityfocus.org/bid/11646
http://www.securityfocus.org/bid/11754
http://www.securityfocus.org/bid/11917
http://www.securityfocus.org/bid/11938
http://www.securityfocus.org/bid/12190
http://www.securityfocus.org/bid/12244
http://www.securityfocus.org/bid/12261
http://www.securityfocus.org/bid/11570

It's front-page news when MS announces a few vulnerabilities, and it slips into obscurity when there's 17 Linux Kernel vulnerabilities recently...

Last Conformist is offline Last Conformist
King
of Calakmul
Jul 2003
time: 06:29
  Old Post 31-01-2005 21:55
Edit/Delete Message Reply w/Quote
#8 Report this post to a moderator
Put an end to popups!

The Linux people don't have enough money that anyone cares if anything bad happens to them.

Urban Ranger is offline Urban Ranger
Apolyton Duke of Off-Topic

Donate to the Red Cross
The City State of Noosphere, CPA special envoy
May 1999
time: 13:29
  Old Post 01-02-2005 08:00
Edit/Delete Message Reply w/Quote
#9 Report this post to a moderator
Support Apolyton buy from Amazon

quote:
Originally posted by Asher
In addition to only affecting systems without NX/XD support ("software" DEP/"sandboxing" instead of "hardware"), it'll also require an exploitable memory error in a system component (there are none known right now) that uses a very specific method of heap allocation, including using heap lookaside lists (which are disabled by default).


The NX support just gives people a false sense of security.

quote:
Originally posted by Asher
In short, . The chances of this being an issue are slim to none, and it's more FUD from the people who claim to hate FUD.


Heard about "smashing the stack" before? Buffer overruns is the single most critical thing to guard against. I wonder why the resident MS fanboy is downplaying this?

quote:
Originally posted by Asher
You'd think the Linux geeks who keep buzzing about this would best spend their time upgrading their linux boxes.


The funny thing is, updating to SP2 does little good.

quote:
Originally posted by Asher
There were 17 Linux kernel vulnerabilities recently...
http://www.securityfocus.org/bid/11491
http://www.securityfocus.org/bid/11492
http://www.securityfocus.org/bid/11533
http://www.securityfocus.org/bid/11488
http://www.securityfocus.org/bid/11695
http://www.securityfocus.org/bid/11921
http://www.securityfocus.org/bid/11937
http://www.securityfocus.org/bid/11715
http://www.securityfocus.org/bid/11939
http://www.securityfocus.org/bid/11646
http://www.securityfocus.org/bid/11754
http://www.securityfocus.org/bid/11917
http://www.securityfocus.org/bid/11938
http://www.securityfocus.org/bid/12190
http://www.securityfocus.org/bid/12244
http://www.securityfocus.org/bid/12261
http://www.securityfocus.org/bid/11570


Yet what are making the CERT list?

quote:
Originally posted by Asher
It's front-page news when MS announces a few vulnerabilities, and it slips into obscurity when there's 17 Linux Kernel vulnerabilities recently...


It's so amusing that MS types are telling us that how Windows is so much more secure than Linux, but even the vaulted SP2 is breached so fast, which enables buffer overruns of all things. "Trustworthy Computing" indeed.

Besides, MS failed to announce this, like usual.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 01-02-2005 08:14 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#10 Report this post to a moderator
Tired of ads?

quote:
Originally posted by Urban Ranger
The NX support just gives people a false sense of security.

So does using Linux or MacOS X, or anything where people tell you you need not worry about viruses.

What's interesting, and what my point was, was that NX/CD does prevent this kind of attack. In fact, this attack just does not work with NX-enabled systems. So saying it gives people a false-sense of security is rather irrelevant...

quote:
Heard about "smashing the stack" before? Buffer overruns is the single most critical thing to guard against. I wonder why the resident MS fanboy is downplaying this?

Where am I downplaying buffer overruns?

This exploit is possible on only non-NX systems, and only in a tiny fraction of possible buffer overrun exploits. That is my point.

And yes, I know about smashing the stack...and I apparently know more about it than you -- this exploit has nothing to do with the stack, it's a heap exploit (specifically when heap lookaside is on).

I can also lecture you on dtors, global offset table exploits, polymorphic shellcode, RST hijacking, and FMS attacks if you wish. For all the **** you guys give my university, you need to realize it is the only university with a hacking & virus writing course. I know more about this stuff than you, and more than you think.

quote:
Yet what are making the CERT list?

What point is it that you're trying to make?

The Linux kernel has 17 recent security vulnerabilities...some of which are remote, not local. When was the last time we even saw a Windows kernel vulnerability? In fact, that's an exercise up to the reader. Show me the last Windows NT kernel vulnerability...

quote:
It's so amusing that MS types are telling us that how Windows is so much more secure than Linux, but even the vaulted SP2 is breached so fast, which enables buffer overruns of all things. "Trustworthy Computing" indeed.

A system with one remote exploit like any one of the latest 17 Linux kernel vulnerabilies is just as insecure as a system with 150.

I don't expect you to understand, you're clearly the Slashdot type who don't know much about the subject. You have a vague high-level understanding, add on your bias and twist and FUD and suddenly it's just pathetic.

This issue has such a remote chance of happening that it's rather worthless. It's an incredibly contrived example that it's useless in the real world, and one that will likely be patched soon.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 01-02-2005 19:38 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#11 Report this post to a moderator
Support Apolyton, buy Civilization III: Complete

Shame on you, UR.

Agathon is offline Agathon
Prince
Leafs 4TW!! - CPA
Dec 2002
time: 00:29
  Old Post 01-02-2005 19:45
Edit/Delete Message Reply w/Quote
#12 Report this post to a moderator
Increase the size of your Attachments

quote:
Actually it'd be the super-hot girl, because everyone is gunning for her.


How little you know of men.

optimus2861 is offline optimus2861
Chieftain
Halifax, NS
Nov 2000
time: 01:29
  Old Post 01-02-2005 21:04
Edit/Delete Message Reply w/Quote
#13 Report this post to a moderator
Support Apolyton buy from Amazon

quote:
Originally posted by Asher
The Linux kernel has 17 recent security vulnerabilities...some of which are remote, not local. When was the last time we even saw a Windows kernel vulnerability? In fact, that's an exercise up to the reader. Show me the last Windows NT kernel vulnerability...

This is a slightly unfair comparison. The WindowsXP kernel has effectively been frozen for -- how long since it came out, three years now? The Linux kernel, specifically the 2.6 kernel, is being continually developed. And the deep hooks between that blasted Internet Explorer and the rest of Windows renders a kernel vulnerability somewhat irrelevant on a Windows box. You hardly need a kernel vulnerability when IE is such a piece of garbage.

At least the Linux 2.2 kernel is still actively maintained; if there were any new NT kernel vulnerabilites found, MS wouldn't fix it any more (I literally mean WindowsNT here, as it's fallen out of support. Hell, MS even gives Windows2000 the shaft to an extent, refusing to backport IE6 SP2 to it for instance).

That being said, I had to download a complete set of KDE 3.2 packages for Mandrake 10.1 for the fifth time last night, and that distro is barely three months old. Meanwhile the KDE developers are working on a beta of 3.4! Seems to me like they're racing ahead on features too much and neglecting security. And I can't get the latest Mandrake kernel to install either -- the bootloader script is crapping out for some obscure reason (and for which I've gotten no advice in two user forums either).

Neither camp is as good as it should be.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 01-02-2005 21:18 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#14 Report this post to a moderator
Help yourself to an AD-FREE life

quote:
Originally posted by optimus2861
This is a slightly unfair comparison. The WindowsXP kernel has effectively been frozen for -- how long since it came out, three years now? The Linux kernel, specifically the 2.6 kernel, is being continually developed. And the deep hooks between that blasted Internet Explorer and the rest of Windows renders a kernel vulnerability somewhat irrelevant on a Windows box. You hardly need a kernel vulnerability when IE is such a piece of garbage.

Don't use IE.

quote:
At least the Linux 2.2 kernel is still actively maintained; if there were any new NT kernel vulnerabilites found, MS wouldn't fix it any more (I literally mean WindowsNT here, as it's fallen out of support.

Eh? Windows NT 4.0 still gets critical security vulnerabilities patched. The latest was on January 17, 2005...: http://www.computerweekly.com/artic...Search=&nPage=1

Support "officially" ended Dec 31, 2004, but critical patches are still being made available.

As for it being unfair -- it doesn't really matter. The XP kernel was modified as recently as Windows XP SP2, and the Windows XP kernel is from 2001. Many of the kernel vulnerabilities in my list affect 2.2, which predates Windows XP by over a year.

NT4 was launched in, what, 1995/1996? And it's still getting fixes ~10 years later?

Apple won't even provide fixes for anything older than a couple years, and I don't know if I've seen a recent Linux 1.x security fix.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 02-02-2005 00:03 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#15 Report this post to a moderator
Inflate your Upload Space

optimus2861 is offline optimus2861
Chieftain
Halifax, NS
Nov 2000
time: 01:29
  Old Post 02-02-2005 00:06
Edit/Delete Message Reply w/Quote
#16 Report this post to a moderator
Support Apolyton, buy Civilization III: Complete

quote:
Originally posted by Asher
Don't use IE.

Believe me, I don't. But I can't get rid of it, either, as you can't remove it from the OS. Then you run into one of those fscking IE-only websites..

quote:
Eh? Windows NT 4.0 still gets critical security vulnerabilities patched. The latest was on January 17, 2005...: http://www.computerweekly.com/artic...Search=&nPage=1

I stand partly corrected:
quote:

On its security site, Microsoft said its engineers had carried out the bulk of the work on fixing the vulnerabilities before the end of 2004 and so it had decided to release a security update for the operating system version as part of its security bulletin.

The company said it did not anticipate doing this for future vulnerabilities that may affect NT4, but added, "We reserve the right to produce updates and to make these updates available when necessary."

It urged users running NT4 Server to migrate to supported operating system versions to prevent potential exposure to vulnerabilities.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 02-02-2005 00:09 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#17 Report this post to a moderator
Avatar Enlargement: We've got the solution

Still, comparing NT4 to kernel 2.2 or even 2.0 is a bit unfair. NT4 predates both of those by years, as well.

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 03-02-2005 00:10 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#18 Report this post to a moderator
Got spare money?

Looks like this is officially nothing but hysteria and FUD from Urban Ranger, as per usual.

http://news.com.com/Microsoft+SP2+s...ml?tag=nefd.top
quote:
Microsoft: SP2 shimmy's not a flaw
Published: February 1, 2005, 3:24 PM PST
By Matt Hines
Staff Writer, CNET News.com

Microsoft downplayed the significance of a reported flaw in its latest update to Windows XP.

Responding to a Russian security company's claim that it found a way to beat a protective element of Microsoft's Windows XP Service Pack 2, the software giant on Tuesday said it does not believe the issue represents a vulnerability. In fact, the company said the technology highlighted by Moscow-based Positive Technologies was never meant to be "foolproof" and added that the reported flaw does not, by itself, put consumers at risk.

"An attacker cannot use this method by itself to attempt to run malicious code on a user's system," Microsoft said in a statement. "There is no attack that utilizes this, and customers are not at risk from the situation."

Last week, Positive reported that the Data Execution Protection tools included in Service Pack 2--code intended to prevent would-be attackers from inserting malicious programs into a PC's memory--opened Windows XP systems up to additional threats. The security company said that two minor mistakes in the implementation of the technology could allow a knowledgeable programmer to sidestep the measures, known as the Data Execution Protection and the Heap Overflow Protection.

But Microsoft representatives disagreed with Positive's interpretation of Data Execution Protection, saying the technology was not created to necessarily foil existing threats but to make developing attacks against Service Pack 2 harder.

In an e-mail message to CNET News.com, Microsoft representatives said the company would continue to modify the technology and would evaluate ways to mitigate the reported method of bypass.

Those "security technologies in Windows XP Service Pack 2 are meant to help make it more difficult for an attacker to run malicious software on the computer as the result of a buffer-overrun vulnerability," the representatives said in the statement. "Our early analysis indicates that this attempt to bypass these features is not security vulnerability."

Positive said that attack programs that use the exploit to get around Windows XP Service Pack 2 protections work reliably, allowing intruders to introduce malicious code onto machines using a second vulnerability that would otherwise not work on Service Pack 2 because of the protection mechanisms.

Yury Maksimov, chief technology officer at the security company, said Positive only publicized the issue after Microsoft refused to act on previous warnings of the flaw that it sent to the software giant. He said he believes the Data Execution Protection does open up potential vulnerabilities.

"In this situation, we decided it would be much safer for the industry to be aware of the new, existing threat," Maksimov wrote in an e-mail. "Such a vulnerability cannot cause a new worm or virus (to appear). But that's exactly the situation when it is much better to know about the problem, than not."

However, at least one industry expert said that Positive's report of the threat may not be completely fair to Microsoft. Peter Lindstrom, a research director at Spire Security, observed that the Data Execution Protection vulnerability is unlikely to be seized upon by hackers. It relates more to core security issues with the design of many different kinds of software, not just tools made by Microsoft, he said.

"Maybe you could classify this problem as a lost opportunity on Microsoft's part to protect Windows better, but that doesn't make it a vulnerability," Lindstrom said.


Funny how UR is ignoring this thread now.

Last edited by Asher on 03-02-2005 at 00:16

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 03-02-2005 23:55 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#19 Report this post to a moderator
Support Apolyton, buy Civilization III: Complete

Such a predictably disappointing performance from UR...

Gatekeeper is offline Gatekeeper
King
United States of America
Feb 2000
time: 23:29
  Old Post 04-02-2005 01:37 Visit Gatekeeper's homepage!
Edit/Delete Message Reply w/Quote
#20 Report this post to a moderator
Avatar Enlargement: We've got the solution

UR and Asher — pistols at high noon!

Asher is offline Asher
King
Calgary, Alberta
Nov 1999
time: 22:29
  Old Post 04-02-2005 02:46 Visit Asher's homepage!
Edit/Delete Message Reply w/Quote
#21 Report this post to a moderator
Support Apolyton, buy Civilization III: Complete

UR has once again fled with his tail between his legs, though.

This is hardly the first time he's done a troll-and-run without knowledge of what he's talking about.

  < Last Thread     Next Thread > Post New Thread     Post A Reply
All times are GMT. The time now is 05:29.
Apolyton Time is 00:29.
    top of page
Rate This Thread:
Forum Jump:
Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is ON
vB code is ON
Smilies are ON
[IMG] code is ON
 




Contact Us - Apolyton Civilization Site - Support Us!

Building a better Apolyton through better information. Click here and take our poll!
Non-US visitors, click here!

Powered by: vBulletin Version 2.0.3
Copyright ©2000, 2001, Jelsoft Enterprises Limited.

Page generated in 0.0672 seconds (93.48% PHP - 6.52% MySQL) with 30 queries
Page Loading Time:

Support Apolyton: Amazon USA | Amazon UK | Amazon DE | Amazon FR |
Support Apolyton and get FREE PLUS, Buy from Chips&Bits: Galactic Civilizations | Galactic Civilizations: Deluxe Edition | Call to Power 2 | Civilization: The Boardgame | GURPS/ Alpha Centauri | Alpha Centauri | Civilization IV | Civilization III: Complete |


Front Page | Civilization IV | Civilization III | Civilization II | Call to Power II | Alpha Centauri | Master of Orion III
Rise of Nations | Galactic Civilizations | Galactic Civilizations II | Misc
Alt.Civs | Civ I | C:CtP I | About | News | Directory | Apolyton Store | Forums | Chat | Columns | Interviews | Newsletter
Scenario League | CSC | Clash of Civs | Spanish Site | CtP Maps | Cradle of Civ | WesW's Ctp1/2 Site | Civ3 Haven

apolyton.net | apolyton.com | civilization2.net | civilization3.net | civilization4.net | civilizationiv.info | calltopower.net | galciv.net | galciv2.net | moo3.net