Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Microsoft Opening Up Vista Kernel To Security Vendors
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
How to Install IE7 Bypassing Genuine Windows Validation »
« Hpguru's Hosts File Error  
dave
Premium,MVM
join:2000-05-04
not in ohio

Re: Microsoft Opening Up Vista Kernel To Security Vendors

So providing an API to retrieve certain (unspecified) information is all that the people complaining about PatchGuard really wanted?

AB
Premium
join:2006-04-04
Leesburg, VA

Re: Microsoft Opening Up Vista Kernel To Security Vendors

said by dave See Profile :

So providing an API to retrieve certain (unspecified) information is all that the people complaining about PatchGuard really wanted?
Dave-
Any chance you could explain to rubes such as myself what actual real-world impact this has on the 'no one can access the kernel' security lock-down of Vista, or would you be lacking enough information at the present time?
Thanks.
dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

Re: Microsoft Opening Up Vista Kernel To Security Vendors

said by AB See Profile :

said by dave See Profile :

So providing an API to retrieve certain (unspecified) information is all that the people complaining about PatchGuard really wanted?
Dave-
Any chance you could explain to rubes such as myself what actual real-world impact this has on the 'no one can access the kernel' security lock-down of Vista, or would you be lacking enough information at the present time?
Thanks.
They seem unrelated to me.

The original complaint was that it was no longer possible to overwrite certain dispatch tables, say for example overwriting the entry that says "when syscall #42 is implemented, jump to the function that implements NtBanana in the kernel". Overwriting the table allows you to seize control when an app calls the NtBanana system service; this can be used for good or evil, and is now no longer possible due to PatchGuard.

Instead of this ability, the security-app vendors are now apparently being provided with calls whereby they can look at certain vague "information" that the kernel knows. This is, on the surface, completely unrelated to being able to patch kernel data structures.

I suppose it all depends on what this "information" might be; the article was maddeningly imprecise. Maybe there's going to be a way to get hooked in to knowing that an app called the NtBanana service without actually intercepting the call.

Nevertheless, it sounds like McAfee/Symatec were screaming that their nuclear weapons were being taken away from them, and now they've been offered a handgun and they're happy again.

This sounds like goodness to me, esp. if the article is correct in that the security apps are simply getting to read info. Security consists in large part of not having more access than the job requires - so if what you actually want is to read something, don't go having the ability to completely alter the system's flow of control.

----
Sorry for the vagueness of this response, I don't know any more about what is really happening than that single article.

AB
Premium
join:2006-04-04
Leesburg, VA

Re: Microsoft Opening Up Vista Kernel To Security Vendors

said by dave See Profile :

. . Sorry for the vagueness of this response, I don't know any more about what is really happening than that single article.
Sorry for the vagueness? Hardly.
An incredibly concise and informative response, considering the freshness of the information available and the time you have had to examine it.
Thank you, Dave. Very, very much!
Forums » Up and Running » Security » SecurityHow to Install IE7 Bypassing Genuine Windows Validation »
« Hpguru's Hosts File Error  


Sunday, 06-Dec 00:24:22 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [122] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· HVAC - Leaving a bedroom window open? [Home Repair & Improvement]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· First commercial tool to crack BitLocker arrives (Updated) [Security]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]