Page 1 of 3 123 LastLast
Results 1 to 25 of 74

Thread: Windows 7's Unfixable Glitch

  1. #1
    Xtreme Member
    Join Date
    Dec 2006
    Posts
    319

    Windows 7's Unfixable Glitch

    http://gear.ign.com/articles/976/976242p1.html

    "A team of researchers located an exploit within the new operating system that can allow hackers to take control of a user's machine during the startup process. The problem was identified by Vipin Kumar and Nitin Kumar, who created a program called VBootKit 2.0 that exploits the weakness and allows a hacker to bypass the machine's hard drive entirely, making it nearly impossible to detect. Once hackers can implement the software, they can then change access permissions, passwords, and gain access to a user's sensitive information. What's worse, a program like the one created by Vipin and Nitin Kumar can be as small as 3KBs, and thus can be spread rapidly. Naturally, problems like these are common during the pre-release beta stages, but Vipin and Nitin Kumar claim that this vulnerability is unique and completely unfixable."
    2x Asus P8Z68-V PRO Bios 0501
    i7 2600K @ 4.6GHz 1.325v / i5 2500K @ 4.4GHz 1.300v
    2x G.SKILL Ripjaws X Series 8GB DDR3 1600
    Plextor M5P 256GB SSD / Samsung 840 Pro 256GB SSD
    Seasonic X-1050 PSU / SeaSonic X Series X650 Gold PSU
    EVGA GTX 690 (+135%/+100MHz/+200MHz/75%) / EVGA GTX 680 SC Signature+ (+130%/+80MHz/+200MHz/70%)


  2. #2
    Xtreme Cruncher
    Join Date
    Aug 2006
    Location
    Denmark
    Posts
    7,747
    So Windows 7 is like any other OS. Also you forgot the most important parts.

    Researchers Vipin Kumar and Nitin Kumar used proof-of-concept code they developed, called VBootkit 2.0, to take control of a Windows 7 virtual machine while it was booting up. They demonstrated how the software works at the conference.

    [ Learn how to secure your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

    "There's no fix for this. It cannot be fixed. It's a design problem," Vipin Kumar said, explaining the software exploits the Windows 7 assumption that the boot process is safe from attack.

    While VBootkit 2.0 shows how an attacker can take control of a Windows 7 computer, it's not necessarily a serious threat. For the attack to work, an attacker must have physical access to the victim's computer. The attack can not be done remotely.
    Having physical access is like...hum...I can boot unix in singleuser mode aswell then and so on.
    Last edited by Shintai; 04-26-2009 at 08:42 AM.
    Crunching for Comrades and the Common good of the People.

  3. #3
    Xtreme Addict
    Join Date
    Aug 2005
    Location
    Washington
    Posts
    1,319
    So... how are hackers supposed to do this remotely? If you have to be there to do it, this seems kinda pointless.

    EDIT: Shintai beat me.

  4. #4
    Xtreme Member
    Join Date
    Feb 2007
    Posts
    241
    Just the other day I discovered another very danguros security glitch, it's called "Leaving your computer unattended"...

  5. #5
    Xtreme Member
    Join Date
    Dec 2008
    Posts
    141
    This story seems like the typical anti-Microsoft fear mongering. Microsoft has their faults but for this to become a widely spread story with headlines to make it look like a deal breaker is really ridiculous. If someone has physical access to a secured system, there are plenty of other security issues to deal with rather than a hole in the OS.

  6. #6
    Xtreme Addict
    Join Date
    Jun 2007
    Location
    United States
    Posts
    1,546
    Quote Originally Posted by tuanster1119 View Post
    This story seems like the typical anti-Microsoft fear mongering. Microsoft has their faults but for this to become a widely spread story with headlines to make it look like a deal breaker is really ridiculous. If someone has physical access to a secured system, there are plenty of other security issues to deal with rather than a hole in the OS.
    Yes. No operating system is completely secure if the user has physical access.

  7. #7
    Xtreme Addict
    Join Date
    May 2006
    Location
    Colorado Springs
    Posts
    1,173
    frickin waste of my time!!!! thanks for wasting my life icecpu

    and Shintai thank you for clearing up this utterly worthless post
    1

  8. #8
    Xtreme Enthusiast
    Join Date
    Dec 2008
    Posts
    811
    No threat at all, pointless, only people who would care about this would be at internet cafes, business and crap where they give users limited access.

  9. #9
    Xtreme Addict
    Join Date
    Apr 2008
    Location
    France
    Posts
    1,210
    already posted, but no problem, there was no feedback there ...yeah there's no threat unless physical access to the PC is first possible.

    http://www.xtremesystems.org/forums/...7&postcount=63
    [SIGPIC][/SIGPIC]

  10. #10
    Xtreme Enthusiast
    Join Date
    Jul 2007
    Location
    Phoenix, AZ
    Posts
    866
    I also created a method the other day for windows 7....and every other operating system and computer out there. Unfortunately I have to have physical access to the computer to use it.


    Its called Baseballbat 1.0 It is completely unfixable and a major threat!!


    My method renders any computer completely useless.
    This post above was delayed 90 times by Nvidia. Cause that's their thing, thats what they do.
    This Announcement of the delayed post above has been brought to you by Nvidia Inc.

    RIGGY
    case:Antec 1200
    MB: XFX Nforce 750I SLI 72D9
    CPU:E8400 (1651/4x9) 3712.48
    MEM:4gb Gskill DDR21000 (5-5-5-15)
    GPU: NVIDIA GTX260 EVGA SSC (X2 in SLI) both 652/1403
    PS:Corsair 650TX
    OS: Windows 7 64-bit Ultimate
    --Cooling--
    5x120mm 1x200mm
    Zalman 9700LED
    Displays: Samsung LN32B650/Samsung 2243BWX/samsung P2350


  11. #11
    Xtreme Cruncher
    Join Date
    Aug 2006
    Location
    Denmark
    Posts
    7,747
    Latest news, besides Windows 7 all Windows versions, OSX, all Linux flavours, all BSD flavours are easily exploitable aswell! World coming to and end!

    We advice to lock the serverrooms!
    Crunching for Comrades and the Common good of the People.

  12. #12
    Xtreme Addict
    Join Date
    Apr 2008
    Location
    France
    Posts
    1,210
    Quote Originally Posted by Decami View Post
    I also created a method the other day for windows 7....and every other operating system and computer out there. Unfortunately I have to have physical access to the computer to use it.


    Its called Baseballbat 1.0 It is completely unfixable and a major threat!!


    My method renders any computer completely useless.
    you're not supposed to post warez on this site

    edit: I mean this is obviously a crack
    Last edited by Logos; 04-26-2009 at 10:08 AM.
    [SIGPIC][/SIGPIC]

  13. #13
    Xtreme Addict
    Join Date
    Aug 2005
    Location
    Germany
    Posts
    2,247
    lol...
    this is as much a security risk as a livecd in a cdrom drive.
    1. Asus P5Q-E / Intel Core 2 Quad Q9550 @~3612 MHz (8,5x425) / 2x2GB OCZ Platinum XTC (PC2-8000U, CL5) / EVGA GeForce GTX 570 / Crucial M4 128GB, WD Caviar Blue 640GB, WD Caviar SE16 320GB, WD Caviar SE 160GB / be quiet! Dark Power Pro P7 550W / Thermaltake Tsunami VA3000BWA / LG L227WT / Teufel Concept E Magnum 5.1 // SysProfile


    2. Asus A8N-SLI / AMD Athlon 64 4000+ @~2640 MHz (12x220) / 1024 MB Corsair CMX TwinX 3200C2, 2.5-3-3-6 1T / Club3D GeForce 7800GT @463/1120 MHz / Crucial M4 64GB, Hitachi Deskstar 40GB / be quiet! Blackline P5 470W

  14. #14
    Xtreme Addict
    Join Date
    Apr 2008
    Location
    France
    Posts
    1,210
    Quote Originally Posted by RaZz! View Post
    lol...
    this is as much a security risk as a livecd in a cdrom drive.
    btw they did something funny on the Suse live cd (latest version). When you attempt to access a drive, EXT3 or NTFS, you get the message, "denied by OS policy"
    [SIGPIC][/SIGPIC]

  15. #15
    Xtreme Addict
    Join Date
    Dec 2005
    Posts
    1,035
    Quote Originally Posted by Decami View Post
    I also created a method the other day for windows 7....and every other operating system and computer out there. Unfortunately I have to have physical access to the computer to use it.


    Its called Baseballbat 1.0 It is completely unfixable and a major threat!!


    My method renders any computer completely useless.


    Your method is very dangerous indeed

    Thanks god I dont grant strangers physical access to my house / PC

  16. #16
    Engineering The Xtreme
    Join Date
    Feb 2007
    Location
    MA, USA
    Posts
    7,217
    already people are trying to bash the crap out of windows 7....

  17. #17
    Xtreme Enthusiast
    Join Date
    Mar 2005
    Location
    North USA
    Posts
    670
    This just in: If a robber has physical access to your whole house, and all the time and privacy he desires, he could STEAL ANYTHING HE WANTED!!!

    HOLY COW! RUN!
    Asus P6T-DLX V2 1104 & i7 920 @ 4116 1.32v(Windows Reported) 1.3375v (BIOS Set) 196x20(1) HT OFF
    6GB OCZ Platinum DDR3 1600 3x2GB@ 7-7-7-24, 1.66v, 1568Mhz
    Sapphire 5870 @ 985/1245 1.2v
    X-Fi "Fatal1ty" & Klipsch ProMedia Ultra 5.1 Speaks/Beyerdynamic DT-880 Pro (2005 Model) and a mini3 amp
    WD 150GB Raptor (Games) & 2x WD 640GB (System)
    PC Power & Cooling 750w
    Homebrew watercooling on CPU and GPU
    and the best monitor ever made + a Samsung 226CW + Dell P2210 for eyefinity
    Windows 7 Utimate x64

  18. #18
    Xtreme Member
    Join Date
    Nov 2005
    Posts
    210
    I really like win 7 and i see a bigger threat of me spilling coffee on the machine than this stupid program.

  19. #19
    Xtreme Addict
    Join Date
    Apr 2008
    Location
    France
    Posts
    1,210
    Quote Originally Posted by SNiiPE_DoGG View Post
    already people are trying to bash the crap out of windows 7....
    you thought they would stop out of respect for this new version they need to kill the idol, over and over again.
    Last edited by Logos; 04-26-2009 at 10:43 AM.
    [SIGPIC][/SIGPIC]

  20. #20
    Xtreme Member
    Join Date
    Sep 2006
    Location
    Philippines
    Posts
    480
    Quote Originally Posted by Decami View Post
    I also created a method the other day for windows 7....and every other operating system and computer out there. Unfortunately I have to have physical access to the computer to use it.


    Its called Baseballbat 1.0 It is completely unfixable and a major threat!!


    My method renders any computer completely useless.
    now that is the unfixable

  21. #21
    Xtreme Addict
    Join Date
    Jun 2005
    Posts
    1,095
    I'd like to try Baseballbat 1.0 on my Mac at my office. Hope that'll help me get rid of it.

  22. #22
    Xtreme Addict
    Join Date
    Apr 2006
    Location
    City of Lights, The Netherlands
    Posts
    2,381
    Quote Originally Posted by SamHughe View Post
    I'd like to try Baseballbat 1.0 on my Mac at my office. Hope that'll help me get rid of it.
    Didn't spilling some coffee over it work? Or do you consider that a waste of your coffee?
    "When in doubt, C-4!" -- Jamie Hyneman

    Silverstone TJ-09 Case | Seasonic X-750 PSU | Intel Core i5 750 CPU | ASUS P7P55D PRO Mobo | OCZ 4GB DDR3 RAM | ATI Radeon 5850 GPU | Intel X-25M 80GB SSD | WD 2TB HDD | Windows 7 x64 | NEC EA23WMi 23" Monitor |Auzentech X-Fi Forte Soundcard | Creative T3 2.1 Speakers | AudioTechnica AD900 Headphone |

  23. #23
    Xtreme Cruncher
    Join Date
    Aug 2008
    Location
    Williamsport, PA
    Posts
    491
    If a hacker has physical access to your desktop, your done period, in any scenario

    Q9300 [Crunch] / XFX GTX285 [Fold] / EVGA 750i
    Two 250GB 7200 / 4GB XMS2 800 / 1Kw XPS PSU / Freezer Pro 7
    10,797 3DMark Vantage / Scythe 120mm Case fans / Vista U. 64
    PS3 - 700 Work Units and going strong!, XPS 720 H2C Case
    Crunching 24/7 on Q9300....might upgrade to an i7

  24. #24
    Banned
    Join Date
    Jun 2008
    Location
    Mi
    Posts
    1,063
    Errr.. haven't we been able to drop a floppy into any computer over the last 15 years and boot off that, bypassing the OS ..?

    (Given: 1st boot device)

  25. #25
    Tyler Durden
    Join Date
    Oct 2003
    Location
    Massachusetts, USA
    Posts
    5,623
    Quote Originally Posted by SamHughe View Post
    I'd like to try Baseballbat 1.0 on my Mac at my office. Hope that'll help me get rid of it.
    I don't believe BaseballBat is compatible with the Power Mac's solid aluminum cases. MetalBaseballBat v1.1 Beta however is expected to add this capability.
    Formerly XIP, now just P.

Page 1 of 3 123 LastLast

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •