Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Microsoft blocks Vista driver 'hack' tool

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Microsoft blocks Vista driver 'hack' tool
LinkBack Thread Tools Display Modes
Old 07-Aug-2007, 03:12 AM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,762
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Microsoft blocks Vista driver 'hack' tool



Microsoft recenlty blocked an application which could have allowed malicious code into the Vista kernel.
The software giant blocked Atsiv which circumvented a significant security feature in the 64-bit version of the operating system.
The security feature--which is intended to prevent unsigned code from being loaded into the Vista 64-bit kernel--is designed to help mitigate malicious kernel drivers typically used by rootkits.
This was "one of the big security features advertised by Microsoft for Vista 64-bit", said Ollie Whitehouse, a security researcher at Symantec, in a blog post.
To load to the kernel, driver code requires a certificate that complies with Microsoft's Kernel Mode Code Signing (KMCS) policy.
Atsivis is a free software utility, produced by Linchpin Labs and OSR, which circumvented KMCS. Atsiv allowed any unsigned driver, including malicious kernel drivers, to be loaded on Vista 64-bit. The tool loaded its own signed driver, but it then allowed unsigned drivers to be loaded through its portable executable (PE) loader. The portable executable format is a data structure with the information necessary for the Windows Vista operating system loader to manage wrapped executable code.
"The (Atsiv) driver isn't malicious in itself, but it could allow malicious code into the kernel. It's punching a big hole through the wall and allowing everything else to climb through," Whitehouse told ZDNet.co.uk.
Using Atsiv, not only could unsigned drivers have been loaded directly to the kernel, but a side effect of the tool using its own PE loader was that it was not visible in Microsoft's standard drivers list, according to Whitehouse. "This is rootkit-type behaviour," said Whitehouse in his blog.
Whitehouse said on 27 July: "In order for Microsoft to mitigate the risk of malicious code utilizing this signed driver to load their own, they are going to have to revoke the signing certificate. It'll be interesting to see how long it takes Microsoft to do this."
Microsoft responded six days later, on Thursday, by blocking Atsiv. Its partner VeriSign revokedthe code signing key.
"Windows Defender released a signature update on 2 August, 2007, that allows detection, blocking and removal of the current Atsiv driver," wrote Windows security architect Scott Field in the Vista security blog. "Classification of the Atsiv software was done in accordance with the objective criteria used by the Windows Defender team to assess the characteristics of potentially unwanted software. Microsoft has worked with partners in the code signing certification authority ecosystem to assess the Atsiv issue. VeriSign has revoked the code signing key used to sign the Atsiv kernel driver, which means the code signing key will no longer be considered valid."
In his blog, Field added that the security team at Microsoft is investigating adding the revoked key to the KMCS revocation list "as an additional defence-in-depth measure".
He tried to play down the significance of the Vista security vulnerability, saying that to install the Atsiv driver, the user must have administrative privileges.
"There is no security vulnerability related to the default case in Windows Vista where users run with limited permissions through the User Account Control feature," wrote Field.
He said that KMCS is "not a security boundary. Rather, it is only one aspect of a defence-in-depth approach to security", adding that KMCS does not guarantee that signed code is not malicious. "KMCS does not provide a means to determine the 'intent' of the signed code--whether it is good or bad--indeed, signed code may contain bugs, be of poor quality, or may be malicious in nature."
Instead, the security value of KMCS is that it provides a means to identify the author of a piece of code, according to Field. "Identifying the source and ownership of code that is loaded by the kernel is a fundamental component of the operating-system and overall-ecosystem trust model," he wrote. "Furthermore, this also provides better transparency to the end user in terms of origin of code that is installed and running on a system."
However, merely identifying the author of malicious code does not prevent that code from executing, said the authors of the Atsiv tool. "Driver signing doesn't prevent malware. It just prohibits freedom to choose, which, on a general-purpose operating system, is simply not acceptable," said one of Atsiv's developers on rootkit.com. "A signed file uniquely identifies the company that developed that file but, when companies can be created and registered in jurisdictions known for protecting the privacy of company founders and directors, you have to ask: what does driver signing actually represent? Absent any control over what the driver actually is or does, this provides no real additional security, other than removing author anonymity," said the Atsiv developer.



Source:Zdnet


------------------


Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT -8. The time now is 02:51 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231