<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Game Over For Windows Vista&#8217;s Security?</title>
	<atom:link href="http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<pubDate>Tue, 02 Dec 2008 08:11:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: Dante</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-441484</link>
		<dc:creator>Dante</dc:creator>
		<pubDate>Sat, 09 Aug 2008 21:04:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-441484</guid>
		<description>A null pointer hack does not need activeX to succeed.  And darkkosmos, if you have Vista, you have .Net :)</description>
		<content:encoded><![CDATA[<p>A null pointer hack does not need activeX to succeed.  And darkkosmos, if you have Vista, you have .Net <img src='http://www.ghacks.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-441284</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sat, 09 Aug 2008 18:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-441284</guid>
		<description>If it uses activex controls everyone knows already those are the most popular form of virus on the net to screw your computer.  I don't dl them unless I need to go to a site for work.</description>
		<content:encoded><![CDATA[<p>If it uses activex controls everyone knows already those are the most popular form of virus on the net to screw your computer.  I don&#8217;t dl them unless I need to go to a site for work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkkosmos</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-441192</link>
		<dc:creator>darkkosmos</dc:creator>
		<pubDate>Sat, 09 Aug 2008 17:46:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-441192</guid>
		<description>So what stops this "legit" looking dll from being marked as a virus? (+I don't even have .net, this is a "if")</description>
		<content:encoded><![CDATA[<p>So what stops this &#8220;legit&#8221; looking dll from being marked as a virus? (+I don&#8217;t even have .net, this is a &#8220;if&#8221;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dante</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-441033</link>
		<dc:creator>Dante</dc:creator>
		<pubDate>Sat, 09 Aug 2008 14:32:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-441033</guid>
		<description>to "darkkosmos" that's because the dll in question carries codes that match a virus signature.  Or it is set to change your registry and it's just warning you that the registry will change.</description>
		<content:encoded><![CDATA[<p>to &#8220;darkkosmos&#8221; that&#8217;s because the dll in question carries codes that match a virus signature.  Or it is set to change your registry and it&#8217;s just warning you that the registry will change.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkkosmos</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440906</link>
		<dc:creator>darkkosmos</dc:creator>
		<pubDate>Sat, 09 Aug 2008 09:02:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440906</guid>
		<description>No I mean it, sometimes my anti virus stops firefox (annoying). and explain to me how a legit looking dll can cause havoc on my system?</description>
		<content:encoded><![CDATA[<p>No I mean it, sometimes my anti virus stops firefox (annoying). and explain to me how a legit looking dll can cause havoc on my system?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dante</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440783</link>
		<dc:creator>Dante</dc:creator>
		<pubDate>Sat, 09 Aug 2008 02:50:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440783</guid>
		<description>Oh, sorry.  Forgot something.  You might be referring to anti-viruses blocking changes to the registry.  But that's only because the OS allows it to block the changes to registry.  .Net dll's will override that - for your own convenience of course.</description>
		<content:encoded><![CDATA[<p>Oh, sorry.  Forgot something.  You might be referring to anti-viruses blocking changes to the registry.  But that&#8217;s only because the OS allows it to block the changes to registry.  .Net dll&#8217;s will override that - for your own convenience of course.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dante</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440776</link>
		<dc:creator>Dante</dc:creator>
		<pubDate>Sat, 09 Aug 2008 02:28:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440776</guid>
		<description>@ darkkosmos.  Your anti-virus doesn't stop behaviors.  It stops programs with codes that match existing virus codes (signatures).  Or it does a heuristic scan to see if it looks even remotely like a virus code.  But your anti-virus does not know what is or is not proper program behavior.

This is why firewalls are recommended as a companion to anti-virus programs.  They show any weird activities that your PC might have.  Like suddenly dialing out to Russia.

And using a null pointer hack, a hacker can load legit functioning dll's in memory.  Than use it to write programs into harddrive and registry.  All perfectly normal to an anti-virus program.  At least, this is what I'm thinking this exploit is.

Of course, I'm not a hacker :)</description>
		<content:encoded><![CDATA[<p>@ darkkosmos.  Your anti-virus doesn&#8217;t stop behaviors.  It stops programs with codes that match existing virus codes (signatures).  Or it does a heuristic scan to see if it looks even remotely like a virus code.  But your anti-virus does not know what is or is not proper program behavior.</p>
<p>This is why firewalls are recommended as a companion to anti-virus programs.  They show any weird activities that your PC might have.  Like suddenly dialing out to Russia.</p>
<p>And using a null pointer hack, a hacker can load legit functioning dll&#8217;s in memory.  Than use it to write programs into harddrive and registry.  All perfectly normal to an anti-virus program.  At least, this is what I&#8217;m thinking this exploit is.</p>
<p>Of course, I&#8217;m not a hacker <img src='http://www.ghacks.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkkosmos</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440659</link>
		<dc:creator>darkkosmos</dc:creator>
		<pubDate>Fri, 08 Aug 2008 21:39:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440659</guid>
		<description>Dante how does memory corruption stop an anti virus? My anti virus terminates any application/loaded dll that behaves strangely and purges it into the "bucket", so even if it gets in it won't work and this all depends on .Net which I don't have and I think my anti virus scans memory too.</description>
		<content:encoded><![CDATA[<p>Dante how does memory corruption stop an anti virus? My anti virus terminates any application/loaded dll that behaves strangely and purges it into the &#8220;bucket&#8221;, so even if it gets in it won&#8217;t work and this all depends on .Net which I don&#8217;t have and I think my anti virus scans memory too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dante</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440527</link>
		<dc:creator>Dante</dc:creator>
		<pubDate>Fri, 08 Aug 2008 17:00:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440527</guid>
		<description>And I'm pretty sure he's using a Null Pointer hack to load the dlls.</description>
		<content:encoded><![CDATA[<p>And I&#8217;m pretty sure he&#8217;s using a Null Pointer hack to load the dlls.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dante</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440524</link>
		<dc:creator>Dante</dc:creator>
		<pubDate>Fri, 08 Aug 2008 16:54:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440524</guid>
		<description>Sorry to disappoint, darkkosmos.  I went and checked out the reports from the BlackHat conference.  It appears to use .net dlls and scripting (any type of scripting).  This will bypass any antivirus out there.  Antivirus programs are not designed for this.</description>
		<content:encoded><![CDATA[<p>Sorry to disappoint, darkkosmos.  I went and checked out the reports from the BlackHat conference.  It appears to use .net dlls and scripting (any type of scripting).  This will bypass any antivirus out there.  Antivirus programs are not designed for this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkkosmos</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440481</link>
		<dc:creator>darkkosmos</dc:creator>
		<pubDate>Fri, 08 Aug 2008 14:27:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440481</guid>
		<description>No fear, having a real antivirus saves you from all those troubles. It's going to be fixed soon though much like the last linux root exploit.</description>
		<content:encoded><![CDATA[<p>No fear, having a real antivirus saves you from all those troubles. It&#8217;s going to be fixed soon though much like the last linux root exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GRTerrero</title>
		<link>http://www.ghacks.net/2008/08/08/game-over-for-windows-vistas-security/#comment-440476</link>
		<dc:creator>GRTerrero</dc:creator>
		<pubDate>Fri, 08 Aug 2008 14:22:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.ghacks.net/?p=5968#comment-440476</guid>
		<description>Crap!

But I have NoScript on Firefox installed.  Still use IE to test blogs and websites.  

Still...CRAP! 

(That's a technical term.)</description>
		<content:encoded><![CDATA[<p>Crap!</p>
<p>But I have NoScript on Firefox installed.  Still use IE to test blogs and websites.  </p>
<p>Still&#8230;CRAP! </p>
<p>(That&#8217;s a technical term.)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
