<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for ckunte.com</title>
	<atom:link href="http://ckunte.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://ckunte.com</link>
	<description>Life, dreams, technology, perfection, rhythm and melody.</description>
	<pubDate>Thu, 21 Aug 2008 18:44:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>Comment on Don&#8217;t give up, Mr. Abdullah by Patrix</title>
		<link>http://ckunte.com/archives/omar-abdullah#comment-16215</link>
		<dc:creator>Patrix</dc:creator>
		<pubDate>Tue, 19 Aug 2008 14:22:01 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/?p=1979#comment-16215</guid>
		<description>Although I don't always support it, he could turn off comments and continue blogging. At least that way, we get to read his views. His detractors could always start blogs and respond if they so prefer.</description>
		<content:encoded><![CDATA[<p>Although I don&#8217;t always support it, he could turn off comments and continue blogging. At least that way, we get to read his views. His detractors could always start blogs and respond if they so prefer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bypassing protection by Govind</title>
		<link>http://ckunte.com/archives/bypassing-protection#comment-16184</link>
		<dc:creator>Govind</dc:creator>
		<pubDate>Thu, 14 Aug 2008 06:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/archives/bypassing-protection#comment-16184</guid>
		<description>Have days become so bad that - Bruce stooped to the yellow journalism :) for eye ball grabbing entries. 


If you are little technical - you will see the focus is on browser(any browser) and btw technique can be applied on every os which will support plugins/access mechanisms.  

Pasting the response of the author verbatim - "I am one of the authors of the paper referenced in the post above. First of all, I'd like to apologize for the sensationalism of the press coverage. Most of the articles about our work are completely inaccurate and full of ridiculous statements. Mark and I had nothing to do with these articles and were not contacted by their authors.

Please read our slides and paper (available from http://taossa.com/) before making any judgements about their content.

What we've done is show that the exploitation prevention mechanisms implemented in Windows Vista (including DEP and ASLR) are ineffective at preventing the exploitation of browser memory corruption vulnerabilities, due to the following factors:

1) the amount of contol an attacker has over the state of the browser process

2) the plugin architecture that allows third party plugins (Java, Flash, Acrobat) which often weaken these protections

3) the architecture of the browsers which run all code in the same process and have no isolation between different components

Our research is focused only on browsers. The protection mechanisms in Vista are still effective at preventing the exploitation of vulnerabilities in server processes, which is why I believe that Vista is still more secure than any previous version of Windows. "

Premise is broken flash/acrobat or another plugin inside any browser. 

If you are like me and run sandboxed browser of either kind and do not click and install everything that is slightly excitable, you will be allright. 

Buffer overflows that are exploitable on X can also be exploited on Y if the RIGHT compromised plugins are available. 

Vista includes a number of mechanisms designed to make it harder to exploit buffer overflows.  

Repeat - No the exploit does not bypass UAC, sandbox browser. It can/will happen on every os/browser with similar kind of vulnerable plugins .

Why IE 7 ran without DEP? 
At the time of shipping, current versions of Sun's Java plugin crashed with DEP enabled. XP SP2 was released in 2004; hmmm jvm software needs to be  DEP compatible. How does one convince JVM vendor to release it. 

Why Flash is not ASLR-unaware or ignorant of SafeSEH.
Becuase they chose to be :).

IL - ASLR needs more votes (not marketing) to do right thing.

Third party plugins have lot to catch up to do with technology landscape change. MS needs to push third party vendors of these plugins utilize the technology to prevent these problems (this paper would not have been possible if DEP/ASLR/safeSEH etc was utilized for the plugins).</description>
		<content:encoded><![CDATA[<p>Have days become so bad that - Bruce stooped to the yellow journalism <img src='http://ckunte.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> for eye ball grabbing entries. </p>
<p>If you are little technical - you will see the focus is on browser(any browser) and btw technique can be applied on every os which will support plugins/access mechanisms.  </p>
<p>Pasting the response of the author verbatim - &#8220;I am one of the authors of the paper referenced in the post above. First of all, I&#8217;d like to apologize for the sensationalism of the press coverage. Most of the articles about our work are completely inaccurate and full of ridiculous statements. Mark and I had nothing to do with these articles and were not contacted by their authors.</p>
<p>Please read our slides and paper (available from <a href="http://taossa.com/" rel="nofollow">http://taossa.com/</a>) before making any judgements about their content.</p>
<p>What we&#8217;ve done is show that the exploitation prevention mechanisms implemented in Windows Vista (including DEP and ASLR) are ineffective at preventing the exploitation of browser memory corruption vulnerabilities, due to the following factors:</p>
<p>1) the amount of contol an attacker has over the state of the browser process</p>
<p>2) the plugin architecture that allows third party plugins (Java, Flash, Acrobat) which often weaken these protections</p>
<p>3) the architecture of the browsers which run all code in the same process and have no isolation between different components</p>
<p>Our research is focused only on browsers. The protection mechanisms in Vista are still effective at preventing the exploitation of vulnerabilities in server processes, which is why I believe that Vista is still more secure than any previous version of Windows. &#8221;</p>
<p>Premise is broken flash/acrobat or another plugin inside any browser. </p>
<p>If you are like me and run sandboxed browser of either kind and do not click and install everything that is slightly excitable, you will be allright. </p>
<p>Buffer overflows that are exploitable on X can also be exploited on Y if the RIGHT compromised plugins are available. </p>
<p>Vista includes a number of mechanisms designed to make it harder to exploit buffer overflows.  </p>
<p>Repeat - No the exploit does not bypass UAC, sandbox browser. It can/will happen on every os/browser with similar kind of vulnerable plugins .</p>
<p>Why IE 7 ran without DEP?<br />
At the time of shipping, current versions of Sun&#8217;s Java plugin crashed with DEP enabled. XP SP2 was released in 2004; hmmm jvm software needs to be  DEP compatible. How does one convince JVM vendor to release it. </p>
<p>Why Flash is not ASLR-unaware or ignorant of SafeSEH.<br />
Becuase they chose to be :).</p>
<p>IL - ASLR needs more votes (not marketing) to do right thing.</p>
<p>Third party plugins have lot to catch up to do with technology landscape change. MS needs to push third party vendors of these plugins utilize the technology to prevent these problems (this paper would not have been possible if DEP/ASLR/safeSEH etc was utilized for the plugins).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Belfry tower by Sneha</title>
		<link>http://ckunte.com/archives/belfry-tower#comment-16151</link>
		<dc:creator>Sneha</dc:creator>
		<pubDate>Fri, 01 Aug 2008 11:47:51 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/archives/belfry-tower#comment-16151</guid>
		<description>Thanks Patrix and HOBO! 
Patrix, I particularly wanted that bit of blue sky to enhance the presence of black clouds. That also adds the motion to the picture making it more lively. My take! :-)</description>
		<content:encoded><![CDATA[<p>Thanks Patrix and HOBO!<br />
Patrix, I particularly wanted that bit of blue sky to enhance the presence of black clouds. That also adds the motion to the picture making it more lively. My take! <img src='http://ckunte.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Belfry tower by HOBO</title>
		<link>http://ckunte.com/archives/belfry-tower#comment-16150</link>
		<dc:creator>HOBO</dc:creator>
		<pubDate>Thu, 31 Jul 2008 19:02:58 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/archives/belfry-tower#comment-16150</guid>
		<description>It looks like Golden tower.
I am amazed and looking at it again &#38; again.
Very well timed photograph.
Congrats !</description>
		<content:encoded><![CDATA[<p>It looks like Golden tower.<br />
I am amazed and looking at it again &amp; again.<br />
Very well timed photograph.<br />
Congrats !</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Belfry tower by Patrix</title>
		<link>http://ckunte.com/archives/belfry-tower#comment-16149</link>
		<dc:creator>Patrix</dc:creator>
		<pubDate>Thu, 31 Jul 2008 18:37:56 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/archives/belfry-tower#comment-16149</guid>
		<description>Beautiful light although I would crop out that bit of blue sky at the bottom.</description>
		<content:encoded><![CDATA[<p>Beautiful light although I would crop out that bit of blue sky at the bottom.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Time taken by Kapil</title>
		<link>http://ckunte.com/archives/time-taken#comment-16139</link>
		<dc:creator>Kapil</dc:creator>
		<pubDate>Sat, 26 Jul 2008 10:18:51 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/archives/time-taken#comment-16139</guid>
		<description>It would be the very opposite when traveling in Mumbai to reach office. 

Car - 1 hour

Train - 40 mins 

Tram / Bicycle - ARE YOU CRAZY?</description>
		<content:encoded><![CDATA[<p>It would be the very opposite when traveling in Mumbai to reach office. </p>
<p>Car - 1 hour</p>
<p>Train - 40 mins </p>
<p>Tram / Bicycle - ARE YOU CRAZY?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pedal pushers by Govind</title>
		<link>http://ckunte.com/archives/pedal-pushers#comment-16110</link>
		<dc:creator>Govind</dc:creator>
		<pubDate>Fri, 18 Jul 2008 06:10:29 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/?p=1910#comment-16110</guid>
		<description>Showers in the office are great boon. I guess we are just privileged folks to have ac/shower in the office. Offcourse need for AC can be lowered down if buildings are constructed looking at local conditions rather than raising the floors on blocks and putting glass and steel. 
I am not sure Mumbai folks can attempt bike in humid weather. People without option do use whatever is available though.</description>
		<content:encoded><![CDATA[<p>Showers in the office are great boon. I guess we are just privileged folks to have ac/shower in the office. Offcourse need for AC can be lowered down if buildings are constructed looking at local conditions rather than raising the floors on blocks and putting glass and steel.<br />
I am not sure Mumbai folks can attempt bike in humid weather. People without option do use whatever is available though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pedal pushers by Chetan</title>
		<link>http://ckunte.com/archives/pedal-pushers#comment-16108</link>
		<dc:creator>Chetan</dc:creator>
		<pubDate>Thu, 17 Jul 2008 14:33:38 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/?p=1910#comment-16108</guid>
		<description>&lt;blockquote&gt;not conducive enough to take a cycle ride and yet make it to office without a heavy sweat.&lt;/blockquote&gt;

Sweat---we all do, particularly in summers. But thankfully, we have showers.</description>
		<content:encoded><![CDATA[<blockquote><p>not conducive enough to take a cycle ride and yet make it to office without a heavy sweat.</p></blockquote>
<p>Sweat&#8212;we all do, particularly in summers. But thankfully, we have showers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pedal pushers by Kapil</title>
		<link>http://ckunte.com/archives/pedal-pushers#comment-16107</link>
		<dc:creator>Kapil</dc:creator>
		<pubDate>Thu, 17 Jul 2008 14:07:13 +0000</pubDate>
		<guid isPermaLink="false">http://ckunte.com/?p=1910#comment-16107</guid>
		<description>I can't imagine myself riding a bicycle to office. Although I would love to like I have seen when in Europe, I think the weather here is just not conducive enough to take a cycle ride and yet make it to office without a heavy sweat. Yes, the idea indeed is a good form of exercise for souls like me who spend most of our waking hours in the office only.</description>
		<content:encoded><![CDATA[<p>I can&#8217;t imagine myself riding a bicycle to office. Although I would love to like I have seen when in Europe, I think the weather here is just not conducive enough to take a cycle ride and yet make it to office without a heavy sweat. Yes, the idea indeed is a good form of exercise for souls like me who spend most of our waking hours in the office only.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
