On mySimon: Backyard Safari Underground Time Capsule
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 2 of 26:
Next »
« Previous
?
This is a hole in F-Secure's user mode app. Not Windows anything. Microsoft isn't pushing the patch F-Secure is for their products.

Now if F-Secure compiled with Microsoft VS7 and the /GH switch the exploit would have caught the buffer over-run with a GPF instead of allowing rouge code. They could have simply run bounds-checker or similiar apps as well and caught this.

Also if they were running Windows XP SP2 with the new AMD or Intel that support NX (no execute) they never could have been the ability for the attacker to run code in either the stack or the data segment.

So Microsoft may have it's holes, but they are doing some pretty cool things to eliminate the impact even for the company's like f-Secure that have their own holes.
Posted by: LinuxHippie   Posted on: 02/11/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Windows is so full of holes ...  George Mitchell | 02/11/05
?  LinuxHippie | 02/11/05
The problem ultimately lies with Windows ...  George Mitchell | 02/11/05
You can't be serious  LinuxHippie | 02/12/05
He didn't say that, WinZealot  Jeff Spicoli | 02/12/05
I'm listening ...  George Mitchell | 02/12/05
Quick question  NonZealot | 02/12/05
Well I am not a newbie ...  George Mitchell | 02/12/05
George the expert  NonZealot | 02/12/05
2 Quick questions  Immanuel Tranz-Mischen | 02/13/05
I'll answer your quick questions  NonZealot | 02/13/05
So I'm not wasting my time any further...  LinuxHippie | 02/14/05
Add yet another one  IT Scion | 02/11/05
Windows is the ONLY OS that REQUIRES antivirus software ...  George Mitchell | 02/11/05
ID 10 T (NT)  LinuxHippie | 02/12/05
Hey wait a minute...  FreeBSD | 02/12/05
No it's not  seosamh_z | 02/13/05
News Flash  Immanuel Tranz-Mischen | 02/13/05
Re: News Flash  PA-ITGuy | 02/13/05
Since when is the OSX kernel...  ShadeTree | 02/14/05
Really?  IT Scion | 02/14/05
my bad  IT Scion | 02/14/05
All AV packages are brutal failures  osreinstall | 02/14/05
I do not run any AV package  osreinstall | 02/13/05
What cave are you living in?  Immanuel Tranz-Mischen | 02/13/05
A very secure cave - NT  osreinstall | 02/13/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline