taviso

linux, programming and security

Update

Wow, I haven't written a post in a long time. I've moved to Switzerland since my last post, still working on the same team. I was originally planning to move to California, but Zurich became an option at some point and meant I didn't have to wrestle with the US immigration system, so this worked out perfectly :-)

I have some saved posts near completion on debugging that I had completely forgotten about, I'll post these soon (or maybe I should move to blogger now, I'll try it out)

Some security news, I'm not usually involved with windows security, but recently did some experimentation with a few tools I've developed or contributed to at work, and tried making them apply to windows software. I actually found several serious vulnerabilities in Internet Explorer using this method, and the first one was just recently released here (more to come):

http://www.microsoft.com/technet/security/Bulletin/MS08-045.mspx

What has surprised me is that nobody has asked me for any details on the issue I reported, Microsoft didn't give away many details (certainly not enough for an IDS sig), and I haven't released any advisory, so I would have expected one of the big IDS vendors whose entire business model is getting these signatures before vulnerabilities are exploited would want to email me before someone bindiffs the patch, but that hasn't happened (even though I would be more than happy to discuss the vulnerability with anyone who cared).

(Not that IDS offer any real protection or represent real security, of course they undoubtedly reduce overall security by dramatically increasing attack surface, but they do seem to be big business)

ITDefense 2008 Next Week

Comments

Anonymous Saturday, August 16, 2008 2:15:20 PM

drew writes: Maybe they've already seen the t-shirts. ;) I wonder if Microsoft provides IDS vendors with more detailed descriptions of vulns.

Anonymous Wednesday, September 3, 2008 12:54:08 AM

Anonymous writes: I would be inclined to suggest that the big players in the IPS world have enough talented people that they can reverse the patch themselves (not officially of course :)

Anonymous Saturday, February 13, 2010 1:57:58 PM

Anonymous writes: What's the bug called?

Anonymous Sunday, April 4, 2010 12:33:11 PM

Julian Correa writes: Hello Travis. I read the post http://www.microsoft.com/brasil/technet/security/bulletin/MS09-062.mspx where it is mentioned his name. I'm a developer. NET and would like to understand how it was done to the attacker can execute code remotely via an integer overflow. My e-mail is julian.g.correa@gmail.com.

Anonymous Sunday, June 13, 2010 6:47:20 AM

Nathalie Y, Pirate party sweden(north) writes: Wow you weren't hard to google, how awesome. Just wanted to send a text in support about the ms bug. I feel like a pirate that is it was the right thing to do. If you didn't they would probably wait for some months to fix it. always "something else" that's more important than customers services. Maybe it's little evil but yeah, its kind of a must these days. Need to flip out and get outrageous to get their response. Their just so self centered as a company. hopefully all their customers fill also find out one day and leave their crap for good. anyways, just a heads up that someone think it was the right thing to do. hugs /Nattie

Anonymous Wednesday, June 16, 2010 1:39:08 PM

Anonymous writes: You are an asshole and a shame to IT community. Mac PhD, Computer Science

Anonymous Thursday, June 17, 2010 8:05:23 AM

Anonymous writes: In response to the above. - You have no clue Mr GCSE IT.

Anonymous Saturday, July 17, 2010 3:24:38 AM

Anonymous writes: Thanks ass clown, I had the format my drive and re-install XP because you want to play with the scrpt kiddies...maybe someday when you grow up you'll be worth a shit!! MORON!!

Anonymous Friday, August 13, 2010 8:36:51 AM

Anonymous writes: Thanx

Anonymous Thursday, March 24, 2011 3:05:02 PM

Анонімний writes: That's perfect that people are able to take the mortgage loans moreover, this opens up new chances.

How to use Quote function:

  1. Select some text
  2. Click on the Quote link

Write a comment

Comment
(BBcode and HTML is turned off for anonymous user comments.)

If you can't read the words, press the small reload icon.


Smilies