Author Topic: All ur Video drivers r belong to h@x0rs  (Read 2996 times)

Offline W1nTry

  • Administrator
  • Akatsuki
  • *****
  • Posts: 11329
  • Country: tt
  • Chakra 109
  • Referrals: 3
    • View Profile
  • CPU: Intel Core i7 3770
  • GPU: Gigabyte GTX 1070
  • RAM: 2x8GB HyperX DDR3 2166MHz
  • Broadband: FLOW
  • Steam: W1nTry
  • XBL: W1nTry
All ur Video drivers r belong to h@x0rs
« on: August 03, 2007, 09:02:04 AM »
Hmm...
Quote
Graphics drivers are malware compliant

DAAMIT, Nvidia fail to stick to spec

By Wily Ferret: Friday 03 August 2007, 10:08
AN INSECURITY expert presenting at Black Hat yesterday succeeded in illustrating the incredible danger posed by Windows Vista drivers - and fingered ATI and Nvidia as having particularly badly written drivers.

Joanna Rutkowska is a leader in the field of virtualisation technology and demonstrated a hack dubbed 'Blue Pill' at last year's Black Hat, the annual hacker conference held in Las Vegas. Using Vista's built-in virtualisation technology, Blue Pill was designed to work as malware, executing itself on boot to give itself hypervisor privileges in the Vista virtualisation system - effectively gaining control of the system in a way that Windows itself could never hope to detect, thus becoming the ultimate rootkit.

Whilst Microsoft claimed to have closed off that exploit for the final release of Vista, there are still plenty of ways to attack Windows Vista and install malicious rootkits, which her presentation yesterday proved. By using the Nvidia driver as a proxy for writing code to the kernel, she showed how a rootkit was able to bypass Vista's kernel protection system, which claims to prevent unsigned and unreliable code causing problems.

"The whole problem in Nvidia," Rutkowska explained, "Is that the driver doesn't do the proper checks and can do a write for an arbitrary registry." By failing to check what it's writing, it's possible for hackers to attach code and have it written into the registry by the Nvidia driver.

It's not just Nvidia's problem, or even ATI's - although both were singled out as particularly bad examples of driver writing. "There are thousands, maybe tens of thousands of third-party drivers that are poorly written and could be a problem," Rutkowska said.

What's worse is that the drivers were so badly written, and their architecture so poorly designed, that a user doesn't even have to have an Nvidia or ATI graphics card installed with the driver to take advantage - it's enough simply to include the driver file with any other job lot of code, stick it anywhere on the C: drive, then proceed to use it as an attack vector.

There's more Black Hat coverage over here, but nothing at the conference seems to be quite as revealing as this presentation. Can Nvidia and ATI go back to the drawing board and re-write their drivers to avoid being a massive malware attack vector? Given the problems they appear to ahve getting Vista working properly at all, we're not entirely confident.

Neither Nvidia nor ATI, Daamit, were able to offer up coherent comments when we asked them to this morning. µ


Carigamers

All ur Video drivers r belong to h@x0rs
« on: August 03, 2007, 09:02:04 AM »

Offline disciple

  • Ancient
  • Kage
  • *****
  • Posts: 1587
  • Chakra 15
  • deus est caritas
    • 360
  • Referrals: 0
    • View Profile
  • CPU: Athlon 64 X2 4000+
  • GPU: RADEON 3650 512 DDR3
  • RAM: 6 GB PC6400
Re: All ur Video drivers r belong to h@x0rs
« Reply #1 on: August 03, 2007, 09:29:58 AM »
u know...  she aint that bad looking, if yuh factor in the whole "female uber hacker" aspect  lol


though she aint acid burn, thas for sure
#406745

Offline W1nTry

  • Administrator
  • Akatsuki
  • *****
  • Posts: 11329
  • Country: tt
  • Chakra 109
  • Referrals: 3
    • View Profile
  • CPU: Intel Core i7 3770
  • GPU: Gigabyte GTX 1070
  • RAM: 2x8GB HyperX DDR3 2166MHz
  • Broadband: FLOW
  • Steam: W1nTry
  • XBL: W1nTry
Re: All ur Video drivers r belong to h@x0rs
« Reply #2 on: August 03, 2007, 09:38:10 AM »
u know...  she aint that bad looking, if yuh factor in the whole "female uber hacker" aspect  lol


though she aint acid burn, thas for sure

O_O which google pics of her did YOU see....

Offline disciple

  • Ancient
  • Kage
  • *****
  • Posts: 1587
  • Chakra 15
  • deus est caritas
    • 360
  • Referrals: 0
    • View Profile
  • CPU: Athlon 64 X2 4000+
  • GPU: RADEON 3650 512 DDR3
  • RAM: 6 GB PC6400
Re: All ur Video drivers r belong to h@x0rs
« Reply #3 on: August 03, 2007, 09:45:44 AM »
lol nah nah.. i was just playin


but i mean...  the pan crash.. the figure aight, but the real draw would be the "female hacker" lol
#406745

Offline Crixx_Creww

  • Akatsuki
  • *****
  • Posts: 9057
  • Country: 00
  • Chakra -12
  • ANBU OF THE HIDDEN VILLAGE FOAK
    • Atari 2600.
  • Referrals: 11
    • View Profile
    • www.crixxcrew.com
  • CPU: Intel Q6600 @3.2 Ghz
  • GPU: Nvidia Xfx geforce 9800GTX+
  • RAM: 8 Gigs Mixed kingston and corsair ddr2
Re: All ur Video drivers r belong to h@x0rs
« Reply #4 on: August 03, 2007, 12:03:07 PM »
hot.. haxxorzz ..chickk.. must.. resist urge .. to.. kidnapp.... grrrr

Carigamers

Re: All ur Video drivers r belong to h@x0rs
« Reply #4 on: August 03, 2007, 12:03:07 PM »

Offline W1nTry

  • Administrator
  • Akatsuki
  • *****
  • Posts: 11329
  • Country: tt
  • Chakra 109
  • Referrals: 3
    • View Profile
  • CPU: Intel Core i7 3770
  • GPU: Gigabyte GTX 1070
  • RAM: 2x8GB HyperX DDR3 2166MHz
  • Broadband: FLOW
  • Steam: W1nTry
  • XBL: W1nTry
Re: All ur Video drivers r belong to h@x0rs
« Reply #5 on: August 13, 2007, 09:31:30 AM »
Update:
Quote
ATI patches "purple pill"

24 hours from start to fix

By Charlie Demerjian: Sunday 12 August 2007, 10:40
THERE IS A VISTA exploit called Purple Pill that targets Vista through graphics drivers. It made a lot of news last week among the security and hacker communities, but how the affected companies responded is quite illuminating.

The way it works is if a vulnerability exists in a driver, since the driver has kernel level access, a moronic design decision on MS's part that we will all pay for over the next few years, attack code can load into the kernel and run rampant. Without getting too much into the joke that is Vista security window dressing, lets just say from that point on, there is pretty much nothing you can do.

The current exploit was said to be a flaw in a graphics driver, and was later revealed to be an ATI driver flaw, specifically an exploit in the installer. The interesting point is not that a graphics driver, or any kernel level driver flaw can expose a system, it is how quickly ATI reacted to it.

According to ATI, it was first notified that its drivers were at fault last Thursday, and as of late Friday, there was still a chance that the fixed drivers could be posted that day. At worst, the patched drivers would be upped on Monday.

The problem centres on the installer rather than the driver, about 4MB of the approximately 35MB package. In a day or so, the flaw was found, patched, tested and posted. [Edit: It looks like the Catalyst 7.7s are now up, so I guess it is Monday] Since the drivers themselves are not changed, only the peripheral programs, they will still be labeled Catalyst 7.8, and scores should not change.

What is comes down to is that a minor bug in a driver installer can own a box, this is a Microsoft problem, not an ATI or Nvidia problem. Both companies can be used to poke a nose into a joke of an MS security model, but rather than holding the messenger's feet to the fire, we should put the blame where it is due, in Redmond.

As a side note, I wonder how NV would react to this situation. Its past reactions to bad news seems to be to shoot the messenger, and I wonder if that carries over to security as well. Since the hot exploit path to Vista for the next few months will be GPU related, I am sure we will find out. Won't this be fun to watch. µ

So where's the Green team's response?

Carigamers

Re: All ur Video drivers r belong to h@x0rs
« Reply #5 on: August 13, 2007, 09:31:30 AM »

 


* ShoutBox

Refresh History
  • Crimson609: yea everything cool how are you?
    August 10, 2022, 07:26:15 AM
  • Pain_Killer: Good day, what's going on with you guys? Is everything Ok?
    February 21, 2021, 05:30:10 PM
  • Crimson609: BOOM covid-19
    August 15, 2020, 01:07:30 PM
  • Shinsoo: bwda 2020 shoutboxing. omg we are in the future and in the past at the same time!
    March 03, 2020, 06:42:47 AM
  • TriniXjin: Watch Black Clover Everyone!
    February 01, 2020, 06:30:00 PM
  • Crimson609: lol
    February 01, 2020, 05:05:53 PM
  • Skitz: So fellas how we go include listing for all dem parts for pc on we profile but doh have any place for motherboard?
    January 24, 2020, 09:11:33 PM
  • Crimson609: :ph34r:
    January 20, 2019, 09:23:28 PM
  • Crimson609: Big up ya whole slef
    January 20, 2019, 09:23:17 PM
  • protomanex: Gyul like Link
    January 20, 2019, 09:23:14 PM
  • protomanex: Man like Kitana
    January 20, 2019, 09:22:39 PM
  • protomanex: Man like Chappy
    January 20, 2019, 09:21:53 PM
  • protomanex: Gyul Like Minato
    January 20, 2019, 09:21:48 PM
  • protomanex: Gyul like XJin
    January 20, 2019, 09:19:53 PM
  • protomanex: Shout out to man like Crimson
    January 20, 2019, 09:19:44 PM
  • Crimson609: shout out to gyal like Corbie Gonta
    January 20, 2019, 09:19:06 PM
  • cold_187: Why allur don't make a discord or something?
    December 03, 2018, 06:17:38 PM
  • Red Paradox: https://www.twitch.tv/flippay1985 everyday from 6:00pm
    May 29, 2018, 09:40:09 AM
  • Red Paradox: anyone play EA Sports UFC 3.. Looking for a challenge. PSN: Flippay1985 :)
    May 09, 2018, 11:00:52 PM
  • cold_187: @TriniXjin not really, I may have something they need (ssd/ram/mb etc.), hence why I also said "trade" ;)
    February 05, 2018, 10:22:14 AM

SimplePortal 2.3.3 © 2008-2010, SimplePortal