On last.fm: Taylor Swift photos and free music!
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 35 of 35:
« Previous
Another full-of-**** article that conveys wrong information
This is not an antivirus technology, and it doesn't prevent buffer overflows.

It's interesting that this one actually notes-- although in a choppy and confusing manner-- that stuff in an overflow can't be executed if NX is used right.

1) Does not prevent buffer overflows
2) Is not an anti-virus technology (it actually is much more significant)

Also, here's an IMPORTANT point:

"Around 50 percent of the Windows security updates from Microsoft in the last two years may have been rendered unnecessary if the technology existed then, according to an analysis by AMD and Microsoft."

This is FLAT WRONG, and I'll tell you why.

The execution flow of the program in a code injection attack will be altered by the changed return pointer on the stack. This means that the program now 'thinks' it has to jump to that code.

Now, the stack is not executable, so the program jumps there, and the CPU refuses to execute code. There is nothing dictating where that thread of that program should go. One of two things happens:

A) The thread catches the termination signal the OS sends, and dies
B) The program (main thread or child thread, either way) catches the signal sent and terminates the program, either by terminating the main thread (implicite end program) or explicitely calling exit().

Imagine you supply hosting, and your web server suddenly gets attacked. It goes down. How much does this cost you to bring back up? How much does it cost when some 12 year old downloads a little program that repetedly does this, denying service to everyone? What if RPC (a core windows service that the OS needs to have running to do certain things) goes down, rendering the system useles until a reboot?

As you can see, this is just a reduction in severity -- in most cases, anyway. It will protect your confidential information, but it won't prevent attacks from doing damage. You can't even claim that Linux can do this with PaX.

Check these wikipedia articles for more detailed information on the subjet:

http://en.wikipedia.org/wiki/NX
http://en.wikipedia.org/wiki/PaX
http://en.wikipedia.org/wiki/Buffer_overflow
http://en.wikipedia.org/wiki/ProPolice

Notice that NX and PaX don't claim to prevent buffer overflows, but ProPolice does. Either way, the program is killed for a violation of policy.
Posted by: bluefoxicy   Posted on: 07/17/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

cpu controls files (DRM)  JWatson77 | 01/08/04
I agree  GRindinAxTaRupy | 01/08/04
This isn't rocket science  MeMyselfAndI_z | 01/09/04
Please  NemesisNL | 01/11/04
What are you talking about?  MeMyselfAndI_z | 01/09/04
Microsoft Windows !  mbraincell@... | 01/08/04
Buffer overflows...  GRindinAxTaRupy | 01/08/04
Its a feature.  George Mitchell | 01/08/04
didnt you know  doh123 | 01/08/04
Not just for windows  Prognosticator | 01/09/04
Good move by the chipmakers ... finally.  George Mitchell | 01/08/04
Good Move ??  nite_w0lf | 01/08/04
Like what your excellency...  JoeMama_z | 01/08/04
Like chip tracking  GRindinAxTaRupy | 01/09/04
You watched to much XFiles...  dg mh | 01/09/04
Right..and the serial numbers put into the PIIIs...  GRindinAxTaRupy | 01/09/04
Get over the Serial Number thing.  ShadeTree | 01/09/04
Find something legitimate to complain about Bit  GRindinAxTaRupy | 01/09/04
Grinder and dignity??? Buwahahaha  No_Ax_to_Grind | 01/10/04
You didn't watch enough  NemesisNL | 01/11/04
Disabled in Montana  Prognosticator | 01/09/04
Tech savvy?  MeMyselfAndI_z | 01/09/04
Not part of DRM or Spyware  ShadeTree | 01/09/04
Not part of DRM ??  nite_w0lf | 01/09/04
Activate is a poor choice of words.  ShadeTree | 01/09/04
Have fun being spied on Bit!  GRindinAxTaRupy | 01/09/04
Way of Life!!!  ShadeTree | 01/09/04
dangerous thinking  Rembrandt Pussyhorse | 01/09/04
You already have!  ShadeTree | 01/09/04
That's exactly what he's saying...  GRindinAxTaRupy | 01/09/04
Hey Axe!  ShadeTree | 01/09/04
Way of Life indeed!!  NemesisNL | 01/11/04
(NT) Since SuSE is shipping 64 bit Linux why wait for Microsoft?  Update victim | 01/09/04
Ahhh....but!!  NemesisNL | 01/11/04
Another full-of-**** article that conveys wrong information  bluefoxicy | 07/17/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement