{"id":394247,"date":"2010-03-05T18:00:38","date_gmt":"2010-03-05T23:00:38","guid":{"rendered":"http:\/\/techie-buzz.com\/?p=19983"},"modified":"2010-03-05T18:00:38","modified_gmt":"2010-03-05T23:00:38","slug":"dep-the-windows-security-feature-has-been-cracked","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/394247","title":{"rendered":"DEP: the Windows Security Feature has been Cracked"},"content":{"rendered":"<p>This week is really bad for security in particular. First we have a crack for RSA coming up, next, the Ubisoft DRM gets cracked in a day and now, DEP meets its fate.<\/p>\n<p>The protection feature in windows which allowed applications to run only in their own memory space has recently been cracked. The feature known as DEP was added to the Windows OS back in XP.<\/p>\n<p>DEP is explained by Wikipedia as,<\/p>\n<blockquote>\n<p>Data Execution Prevention (DEP) is a security feature included in modern Microsoft Windows operating systems that is intended to prevent an application or service from executing code from a non-executable memory region. This helps prevent certain exploits that store code via a buffer overflow, for example.<\/p>\n<\/blockquote>\n<p>Berend-Jan Wever, a Google security software engineer has recently achieved this feat through a buffer overflow attack. A malicious piece of code is executed to take control of a certain part of the memory which then acts as the bot area to run malware codes. The exact nature of the exploit has been explained by Weaver and he has also remarked that it is a matter of days before a cracker takes advantage of this, now that he has laid out the complete process to the attack.<\/p>\n<p>Weaver writes,<\/p>\n<blockquote>\n<p>I am releasing this because I feel it helps explain why ASLR+DEP are not a mitigation to put a lot of faith in, especially on x86 platforms. 32-bits does not provide sufficient address space to randomize memory to the point where guessing addresses becomes impractical, considering heap spraying can allow an attacker to allocate memory across a considerable chunk of the address space and in a highly predictable location.<\/p>\n<\/blockquote>\n<p>This means all 32 bit operating systems and hardwares are insecure! I tend to use Linux more than Windows. Even while connecting to the Internet, Linux works amazingly faster than Windows. And about security, Windows is not even in the league of Linux.<\/p>\n<p>Which Operating System do you use currently? How secure do you feel using it? How often do you face virus problems? Share your views with me.<\/p>\n<div style=\"font-size:12px\">\n<strong>Share:<\/strong><br \/>\n<a href=\"http:\/\/techie-buzz.com\/tech-news\/dep-windows-security-feature-cracked.html#commentrespond\" rel=\"bookmark\" >Comment on This Post<\/a> |<br \/>\n<a href=\"http:\/\/twitter.com\/home?source=techiebuzz&#038;status=DEP:%20the%20Windows%20Security%20Feature%20has%20been%20Cracked%20http%3A%2F%2Fbit.ly%2Fbvx7Ny%20via%20@techiebuzzer\" rel=\"bookmark\" >Tweet This<\/a> |<br \/>\n<a href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/techie-buzz.com\/tech-news\/dep-windows-security-feature-cracked.html\" rel=\"bookmark\" >Share on Facebook<\/a> |<br \/>\n<a href=\"http:\/\/del.icio.us\/post?url=http:\/\/techie-buzz.com\/tech-news\/dep-windows-security-feature-cracked.html&#038;title=DEP:%20the%20Windows%20Security%20Feature%20has%20been%20Cracked\" rel=\"bookmark\" >Save to Delicious<\/a> |<br \/>\n<a href=\"http:\/\/www.stumbleupon.com\/submit?url=http:\/\/techie-buzz.com\/tech-news\/dep-windows-security-feature-cracked.html\" rel=\"bookmark\" >Stumble This<\/a> |<br \/>\n<a href=\"http:\/\/digg.com\/submit?phase=2&#038;url=http:\/\/techie-buzz.com\/tech-news\/dep-windows-security-feature-cracked.html&#038;title=DEP:%20the%20Windows%20Security%20Feature%20has%20been%20Cracked\" rel=\"bookmark\" >Digg This<\/a> |<br \/>\n<a href=\"http:\/\/www.reddit.com\/submit?url=http:\/\/techie-buzz.com\/tech-news\/dep-windows-security-feature-cracked.html&#038;title=DEP:%20the%20Windows%20Security%20Feature%20has%20been%20Cracked\" rel=\"bookmark\" >Reddit This<\/a>\n<\/div>\n<div><strong style=\"font-size:11px;\">TAGS:<\/strong> <span style=\"text-transform:uppercase;font-size:11px;\"><a href=\"http:\/\/techie-buzz.com\/tag\/dep\" rel=\"tag\">DEP<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/security\" rel=\"tag\">Security<\/a><\/span><br \/>\n<\/small><\/div>\n<div style=\"background:#E1E1E1; border: dotted 1px; padding:5px; margin-top:5px;font-size:11px\">\n<a href=\"http:\/\/techie-buzz.com\/tech-news\/dep-windows-security-feature-cracked.html\" title=\"DEP: the Windows Security Feature has been Cracked\">DEP: the Windows Security Feature has been Cracked<\/a> originally appeared on <a href=\"http:\/\/techie-buzz.com\" title=\"Techie Buzz\">Techie Buzz<\/a> written by Chinmoy Kanjilal on Friday 5th March 2010 06:00:38 PM. Please read the <a href=\"http:\/\/techie-buzz.com\/terms-of-use\">Terms of Use<\/a> for fair usage guidance. <\/div>\n<p><\/p>\n<h2>Don&#8217;t miss these Related Posts:<\/h2>\n<ul>\n<li><a href=\"http:\/\/techie-buzz.com\/windows\/security-flaw-windows-7.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Old Security Flaw, Still Found in Windows 7<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/tech-news\/1024-bit-rsa-cracked.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >1024 bit RSA Cracked, new Milestone<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/linux-tips\/windows-as-default-in-grub.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >How to set Windows as Default OS in Grub<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/featured\/microsoft-windows-goes-open-source.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Microsoft Windows Goes Open Source<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/linux-distros\/backtrack-linux-distro-white-hat.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Backtrack : Linux Distro for the White Hat<\/a><\/li>\n<\/ul>\n<h2>Join Techie Buzz on Your Favorite Social Networking Sites<\/h2>\n<ul>\n<li><a href=\"http:\/\/go.techie-buzz.com\/facebookfanrss\" title=\"Become a Techie Buzz fan on Facebook\">Become a Techie Buzz fan on Facebook<\/a><\/li>\n<li><a href=\"http:\/\/go.techie-buzz.com\/twitterrss\" title=\"Follow Techie Buzz on Twitter\">Follow Techie Buzz on Twitter<\/a><\/li>\n<\/ul>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/bQQGpjLea4lhn_TZdh_5IXx4VEc\/0\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/bQQGpjLea4lhn_TZdh_5IXx4VEc\/0\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/bQQGpjLea4lhn_TZdh_5IXx4VEc\/1\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/bQQGpjLea4lhn_TZdh_5IXx4VEc\/1\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/techiebuzz\/~4\/ShuMQvqQ-p4\" height=\"1\" width=\"1\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week is really bad for security in particular. First we have a crack for RSA coming up, next, the Ubisoft DRM gets cracked in a day and now, DEP meets its fate. The protection feature in windows which allowed applications to run only in their own memory space has recently been cracked. The feature [&hellip;]<\/p>\n","protected":false},"author":1821,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-394247","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/394247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/1821"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=394247"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/394247\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=394247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=394247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=394247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}