BugTraq
Firewire Attack on Windows Vista Mar 05 2008 03:53PM
Bernhard Mueller (research sec-consult com) (2 replies)
RE: Firewire Attack on Windows Vista Mar 05 2008 09:30PM
Roger A. Grimes (roger banneretcs com) (4 replies)
As somewhat indicated in the paper itself, these types of physical DMA attacks are possible against any PC-based OS, not just Windows. If that's true, why is the paper titled around Windows Vista?

I guess it makes headlines faster. But isn't as important, if not more important, to say all PC-based systems have the same underlying problem? That it's a broader problem needing a broader solution, instead of picking on one OS vendor to get headlines?

[Disclaimer: I'm a full-time Microsoft employee.]

Roger

*****************************************************************
*Roger A. Grimes, InfoWorld, Security Columnist
*CPA, CISSP, CISA, MCSE: Security (2000/2003), CEH, yada...yada...
*email: roger_grimes (at) infoworld (dot) com [email concealed] or roger (at) banneretcs (dot) com [email concealed]
*Author of Windows Vista Security: Securing Vista Against Malicious Attacks (Wiley)
*http://www.amazon.com/Windows-Vista-Security-Securing-Malicious/dp/0470
101555
*****************************************************************

-----Original Message-----
From: Bernhard Mueller [mailto:research (at) sec-consult (dot) com [email concealed]]
Sent: Wednesday, March 05, 2008 10:54 AM
To: Full Disclosure; Bugtraq
Subject: Firewire Attack on Windows Vista

Hello,

In the light of recent discussions about firewire / DMA hacks, we would like to throw in some of the results of our past research on this topic (done mainly by Peter Panholzer) in the form of a short whitepaper. In this paper, we demonstrate that the firewire unlock attack (as implemented in Adam Boileau´s winlockpwn) can be used against Windows Vista.

The paper is available at:

http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.
pdf

Best regards,

Bernhard

--
_________________________________________

Bernhard Mueller
Security Consultant

SEC Consult Unternehmensberatung GmbH
www.sec-consult.com

A-1190 Vienna, Mooslackengasse 17
phone +43 1 8903043 34
fax +43 1 8903043 15
mobile +43 676 840301 718
email b.mueller (at) sec-consult (dot) com [email concealed]

Firmenbuch Wiener Neustadt: 227896t, UID: ATU56165223
Firmensitz: Prof. Dr. Stephan Korenstraße 10, A-2700 Wiener Neustadt

Advisor for your information security.

[ reply ]
RE: Firewire Attack on Windows Vista Mar 06 2008 10:01AM
bzhbfzj3001 sneakemail com (1 replies)
Re: Firewire Attack on Windows Vista Mar 07 2008 07:51AM
Tonnerre Lombard (tonnerre lombard sygroup ch) (1 replies)
Re: Firewire Attack on Windows Vista Mar 07 2008 06:59PM
Nathanael Hoyle (nhoyle hoyletech com)
Re: Firewire Attack on Windows Vista Mar 06 2008 07:54AM
Tonnerre Lombard (tonnerre lombard sygroup ch)
Re: Firewire Attack on Windows Vista Mar 06 2008 12:57AM
Daniel O'Connor (doconnor gsoft com au)
Re: Firewire Attack on Windows Vista Mar 06 2008 12:37AM
Peter Watkins (peterw usa net) (1 replies)
RE: Firewire Attack on Windows Vista Mar 06 2008 05:50PM
Larry Seltzer (Larry larryseltzer com) (2 replies)
RE: Firewire Attack on Windows Vista Mar 06 2008 09:11PM
Thor (Hammer of God) (thor hammerofgod com)
Re: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:00PM
Tim (tim-security sentinelchicken org) (2 replies)
RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 05:42PM
Thor (Hammer of God) (thor hammerofgod com) (1 replies)
RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 07:40PM
Thor (Hammer of God) (thor hammerofgod com) (1 replies)
RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 07:44PM
Larry Seltzer (Larry larryseltzer com) (1 replies)
RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 07:51PM
Larry Seltzer (Larry larryseltzer com)
RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:13PM
Larry Seltzer (Larry larryseltzer com) (1 replies)
Re: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:20PM
Tim (tim-security sentinelchicken org) (1 replies)
RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:35PM
Larry Seltzer (Larry larryseltzer com) (1 replies)
Re: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:44PM
Tim (tim-security sentinelchicken org)
Re: Firewire Attack on Windows Vista Mar 05 2008 06:29PM
Thierry Zoller (Thierry Zoller lu)


 

Privacy Statement
Copyright 2010, SecurityFocus