|
BugTraq
Firewire Attack on Windows Vista Mar 05 2008 03:53PM Bernhard Mueller (research sec-consult com) (2 replies) RE: Firewire Attack on Windows Vista Mar 05 2008 09:30PM Roger A. Grimes (roger banneretcs com) (4 replies) RE: Firewire Attack on Windows Vista Mar 06 2008 10:01AM bzhbfzj3001 sneakemail com (1 replies) Re: Firewire Attack on Windows Vista Mar 07 2008 07:51AM Tonnerre Lombard (tonnerre lombard sygroup ch) (1 replies) Re: Firewire Attack on Windows Vista Mar 06 2008 07:54AM Tonnerre Lombard (tonnerre lombard sygroup ch) Re: Firewire Attack on Windows Vista Mar 06 2008 12:37AM Peter Watkins (peterw usa net) (1 replies) RE: Firewire Attack on Windows Vista Mar 06 2008 05:50PM Larry Seltzer (Larry larryseltzer com) (2 replies) RE: Firewire Attack on Windows Vista Mar 06 2008 09:11PM Thor (Hammer of God) (thor hammerofgod com) Re: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:00PM Tim (tim-security sentinelchicken org) (2 replies) RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 05:42PM Thor (Hammer of God) (thor hammerofgod com) (1 replies) RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 07:40PM Thor (Hammer of God) (thor hammerofgod com) (1 replies) RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 07:44PM Larry Seltzer (Larry larryseltzer com) (1 replies) RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 07 2008 07:51PM Larry Seltzer (Larry larryseltzer com) RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:13PM Larry Seltzer (Larry larryseltzer com) (1 replies) Re: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:20PM Tim (tim-security sentinelchicken org) (1 replies) RE: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:35PM Larry Seltzer (Larry larryseltzer com) (1 replies) Re: [Full-disclosure] Firewire Attack on Windows Vista Mar 06 2008 08:44PM Tim (tim-security sentinelchicken org) |
|
Privacy Statement |
> As somewhat indicated in the paper itself, these types of physical
> DMA attacks are possible against any PC-based OS, not just Windows.
> If that's true, why is the paper titled around Windows Vista?
>
> I guess it makes headlines faster. But isn't as important, if not
> more important, to say all PC-based systems have the same underlying
> problem? That it's a broader problem needing a broader solution,
> instead of picking on one OS vendor to get headlines?
Well it IS a new kid on the block, other systems have already had this
problem reported.. It would certainly be more interesting if Vista
wasn't vulnerable though :)
That said, according to the fwohci source in FreeBSD you have to
explicitly enable this feature and the fwohci man page says it is
mandatory for SBP. It would not be too difficult to disable it by
default unless and SBP device is in use. Even in that case it is
apparently possible to limit the access granted to a particular device
(eg only allow it for the places you expect the device to write to).
--
Daniel O'Connor software and network engineer
for Genesis Software - http://www.gsoft.com.au
"The nice thing about standards is that there
are so many of them to choose from."
-- Andrew Tanenbaum
GPG Fingerprint - 5596 B766 97C0 0E94 4347 295E E593 DC20 7B3F CE8C
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.4 (FreeBSD)
iD8DBQBHz0Gd5ZPcIHs/zowRAvFgAJ9KlcoTYPwtI9eiWFpWhmQhy1vUmACffCLp
hwvs7h13ni9NT59s4yn/j1M=
=fkHh
-----END PGP SIGNATURE-----
[ reply ]