Hackers Can Break Into Vista Through Your Browser
Monday, August 18th, 2008Leave it to some smart folks at black hat to work out a way to jump out of the browser, and right into your operating system.
The full paper on the hack is right here, and overall presents some interesting viewpoints into not only how Vista is secured, but how the hackers were able to escape out of the security system to load code of choice through the browser.
In a presentation at the Black Hat briefings, Mark Dowd of IBM Internet Security Systems (ISS) and Alexander Sotirov, of VMware Inc. will discuss the new methods they’ve found to get around Vista protections such as Address Space Layout Randomization(ASLR), Data Execution Prevention (DEP) and others by using Java, ActiveX controls and .NET objects to load arbitrary content into Web browsers. Source: Techtarget




