ROP Mitigations Bypassed
ROP Mitigations Bypassed
Written by Andrew Johnson   
Monday, 13 August 2012

Whenever you improve your security fence, the dedicated intruder will find another way in. This has already happened to the latest release of Microsoft's anti-hacking toolkit, thereby defeating the ROPGuard protection that won a $50,000 prize.

Microsoft's BlueHat Prize for defenses against attacks on memory vulnerabilities was organized in conjunction with the annual BlackHat conference. The three prize winners all suggested solutions to counter ROP attacks and even before the prizes had been presented one of these had been put to work in a free tool that Microsoft makes available to sys admins.

Microsoft's General Manager for Trustworthy Computing Security, Matt Thomlinson, announced the latest version of its Enhanced Mitigation Experience Toolkit (EMET 5.3) on July 25 stating:

I’m excited to announce that we’ve already been able to incorporate one of these winning technologies into our free Enhanced Mitigation Experience Toolkit (EMET) 3.5 technology preview. The new Tech Preview of EMET offers four new checks based on Ivan Fratric’s ROP exploit mitigation to help prevent attacks utilizing ROP techniques.


rop

 

It took barely two weeks before a security researcher announced on his new REP RET blog that he had bypassed these new ROP Mitigations. Here is the You Tube video that demonstrate the exploit:

 

More details, including the asm code and the Kernelbase method used for a second exploit, can be found via the blog post.

More Information

Bypassing EMET 3.5's ROP Mitigation

Related Articles

BlueHat Prizes Awarded

 

justjsquare

 



 

Comments




or email your comment to: comments@i-programmer.info

 

To be informed about new articles on I Programmer, install the I Programmer Toolbar, subscribe to the RSS feed, follow us on, Twitter, Facebook, Google+ or Linkedin,  or sign up for our weekly newsletter.

 

Banner


New Record For Simultaneously Dancing Robots
26/05/2018

The latest Guinness World Record for the largest number of robots dancing simultaneously was set on February 1st 2018 during the San Remo music festival in Rome when 1372 sub-knee-high robots wer [ ... ]



TypeScript Adds Unused Span Reporting
07/06/2018

The latest release of TypeScript is now available with improvements to the editor including support for unused span reporting; the ability to convert properties to getter/setter; and the choice of mov [ ... ]


More News

Last Updated ( Monday, 13 August 2012 )
 
 

   
Banner
RSS feed of news items only
I Programmer News
Copyright © 2018 i-programmer.info. All Rights Reserved.
Joomla! is Free Software released under the GNU/GPL License.