BetaONE will rise again!


Reply
  #1  
Old 17th May 07, 02:08 AM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,079
NewsBot will become famous soon enough
Researcher Reveals 2-Step Vista UAC Hack
Robert Paveza, a senior Web application developer with Web-based marketing company Terralever, has uncovered a two-step process for exploiting Windows Vista's User Account Control. In his published paper, Paveza said that the vulnerability uses a two-part attack vector against a default Vista installation. The first step requires that a proxy infection tool be downloaded and run without elevation. That software can behave as the victim expects it to while it sets up a second malicious payload in the background. "For instance, if users believe they are downloading a 'Pac-Man' clone, such a game could be run while the malicious software did its work in the background. This pattern of infection follows the typical Trojan horse model, piggybacking on what may be otherwise legitimate software," said Paveza.

Microsoft is aware of demonstrations that "purport" to show how a Vista system can be attacked. A Microsoft spokesperson said the demonstration provided by Paveza is of actions an attacker can take on a system that already has been compromised by another means: "With this in mind, it is important to note that user interaction is required for the initial infection of the Trojan to occur. The user must open the attacker's malicious executable. Furthermore, the successive social engineering attempt will only be successful if the user inadvertently clicks on the malicious shortcut. In fact, at this point, the user must be part of the local administrator's group or provide administrator credentials at the UAC prompt."

View: User-Prompted Elevation of Unintended Code in Windows Vista (PDF)
News source: eWeek

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
M$ 'wait-and-see' on Vista BIOS hack Alpine BetaONE News 0 12th Apr 07 06:23 PM
Hack claims Vista to ship on December 5th Alpine BetaONE News 0 13th Oct 06 10:55 PM
M$ Vista is still a mess Alpine BetaONE News 0 11th Sep 06 01:06 PM
Microsoft: Push the Windows Vista date back NewsBot NeoWin News 0 4th Aug 06 07:00 PM
Microsoft Plans Six Core Windows Vista Versions Alpine BetaONE News 0 20th Feb 06 09:37 PM


All times are GMT +1. The time now is 12:14 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.