Jump to content

Trend Micro: Windows 8 is very secure but still has attack points


nsane.forums

Recommended Posts

nsane.forums

A security researcher says that Windows 8 is more secure than Windows 7 but still has at least three attack points that in, theory, could be exploited by hackers.

Windows 8 is looking like it will be a more secure operating system to install than Windows 7, but that doesn't mean it's 100 percent. A security researcher claims that he has found at least three attack points in Windows 8 that could leave the OS open to exploits.

Computerworld India reports that, during a presentation at the recent Black Hat security conference, Sung-ting Tsai of Trend Micro said the three attack points are the kernel level advanced local procedure call, the component object model (COM) application programming interface and the Windows Runtime API. So far, Tsai says he has been unable to create anything that exploits these attack points.

However, that doesn't mean that exploits could not be found by someone dedicated to discovering one. The article states that Tsai developed an attack method against the Windows Runtime API. Tsai says he launched an attack " ... via fuzzing -- sending it random commands to see if they cause the API to malfunction and create a vulnerability."

Tsai claims that anyone using this method would need some time and some luck to find a true exploit and he claims he has had some luck in this area.

Tsai previously found a memory corruption issue in the Consumer Preview version of Windows 8. He reported the problem to Microsoft who later patched it with the launch of the Release Preview build.

So even though three weaknesses have been found, it does not mean that they can be exploited, yet. Seeing as Tsai already reported previous weaknesses to Microsoft, hopefully these three issues will be passed along as well to help make Windows 8, the most secure version of Windows ever.

Posted Image View: Original Article

Link to comment
Share on other sites


  • Replies 1
  • Views 1.2k
  • Created
  • Last Reply
jimbojet2011

These are the real guys and a lot more!

That keeps the antivirus war alive

We dumb-asses keep on bying antivirus apps and firewalls.

And they keep on writing the bad codes :angry:

The formal owner of McAfee was busted last time, I guess its not for stealing money or whatever........

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...