Click here to Skip to main content
15,888,579 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
GeneralRe: New robotic hand named after Luke Skywalker helps amputee touch and feel again Pin
Joe Woodbury21-Nov-17 7:02
professionalJoe Woodbury21-Nov-17 7:02 
NewsMathematician's study of 'swarmalators' could direct future science Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
NewsMETI space messages invite aliens to communicate with Earth Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
GeneralRe: METI space messages invite aliens to communicate with Earth Pin
Sascha Lefèvre19-Nov-17 21:45
professionalSascha Lefèvre19-Nov-17 21:45 
NewsWindows 8 onwards incorrectly implements ASLR security feature, but you can fix it Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
GeneralRe: Windows 8 onwards incorrectly implements ASLR security feature, but you can fix it Pin
Dan Neely20-Nov-17 2:54
Dan Neely20-Nov-17 2:54 
GeneralRe: Windows 8 onwards incorrectly implements ASLR security feature, but you can fix it Pin
Randor 20-Nov-17 7:07
professional Randor 20-Nov-17 7:07 
GeneralRe: Windows 8 onwards incorrectly implements ASLR security feature, but you can fix it Pin
Dan Neely20-Nov-17 7:32
Dan Neely20-Nov-17 7:32 
Randor wrote:
Dan Neely wrote:
ASLR is only bugged in EMET mode;


That's completely false.


The CERT warning itself says otherwise.

The Problem

Both EMET and Windows Defender Exploit Guard enable system-wide ASLR without also enabling system-wide bottom-up ASLR. Although Windows Defender Exploit guard does have a system-wide option for system-wide bottom-up-ASLR, the default GUI value of "On by default" does not reflect the underlying registry value (unset). This causes programs without /DYNAMICBASE to get relocated, but without any entropy. The result of this is that such programs will be relocated, but to the same address every time across reboots and even across different systems.
Impact

Windows 8 and newer systems that have system-wide ASLR enabled via EMET or Windows Defender Exploit Guard will have non-DYNAMICBASE applications relocated to a predictable location, thus voiding any benefit of mandatory ASLR. This can make exploitation of some classes of vulnerabilities easier.


It repeatedly says the problem is only with EMET not fulling enabling ASLR.
Did you ever see history portrayed as an old man with a wise brow and pulseless heart, weighing all things in the balance of reason?
Is not rather the genius of history like an eternal, imploring maiden, full of fire, with a burning heart and flaming soul, humanly warm and humanly beautiful?
--Zachris Topelius

Training a telescope on one’s own belly button will only reveal lint. You like that? You go right on staring at it. I prefer looking at galaxies.
-- Sarah Hoyt

GeneralRe: Windows 8 onwards incorrectly implements ASLR security feature, but you can fix it Pin
Randor 20-Nov-17 8:00
professional Randor 20-Nov-17 8:00 
GeneralRe: Windows 8 onwards incorrectly implements ASLR security feature, but you can fix it Pin
Dan Neely20-Nov-17 8:06
Dan Neely20-Nov-17 8:06 
GeneralRe: Windows 8 onwards incorrectly implements ASLR security feature, but you can fix it Pin
Randor 20-Nov-17 8:46
professional Randor 20-Nov-17 8:46 
NewsLiving on the Plateau Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
GeneralRe: Living on the Plateau Pin
BillWoodruff20-Nov-17 18:56
professionalBillWoodruff20-Nov-17 18:56 
NewsGovernment outlines when it will disclose or exploit software vulnerabilities Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
GeneralRe: Government outlines when it will disclose or exploit software vulnerabilities Pin
Eddy Vluggen20-Nov-17 0:11
professionalEddy Vluggen20-Nov-17 0:11 
NewsGitHub to devs: Now you'll get security alerts on flaws in popular software libraries Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
NewsAnnouncing the Windows Compatibility Pack for .NET Core Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
NewsMicrosoft and GitHub team up to take Git virtual file system to macOS, Linux Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
NewsMicrosoft abandons typical Patch Tuesday playbook to fix Equation Editor flaw Pin
Kent Sharkey19-Nov-17 18:01
staffKent Sharkey19-Nov-17 18:01 
NewsKaspersky blames NSA hack on infected Microsoft software Pin
Kent Sharkey16-Nov-17 14:46
staffKent Sharkey16-Nov-17 14:46 
GeneralRe: Kaspersky blames NSA hack on infected Microsoft software Pin
Rick York16-Nov-17 15:50
mveRick York16-Nov-17 15:50 
GeneralRe: Kaspersky blames NSA hack on infected Microsoft software Pin
BillWoodruff16-Nov-17 19:32
professionalBillWoodruff16-Nov-17 19:32 
GeneralRe: Kaspersky blames NSA hack on infected Microsoft software Pin
KarstenK16-Nov-17 20:13
mveKarstenK16-Nov-17 20:13 
NewsAnnouncing SQL Operations Studio for preview Pin
Kent Sharkey16-Nov-17 12:31
staffKent Sharkey16-Nov-17 12:31 
GeneralRe: Announcing SQL Operations Studio for preview Pin
Rob Grainger17-Nov-17 3:29
Rob Grainger17-Nov-17 3:29 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.