Sandman – Read the Windows Hibernation File

Monday, May 5th, 2008

This is a pretty new tool and a very cool one, Hibernation is a fairly new feature for Windows so it’s good to see a new tool targeting that. Microsoft provides a feature called Hibernation also know as suspend to disk that aims to save the system state into an undocumented ...

Microsoft Abandons Yahoo Acquisition

Saturday, May 3rd, 2008

Microsoft has dropped its nearly three-month-long pursuit of Yahoo, ending a historic acquisition attempt whose failure takes Microsoft back to square one in its quest to boost its online business to better compete against Google. "We continue to believe that our proposed acquisition made sense for Microsoft, Yahoo and the market ...

Keep Vista’s User Account Control on guard duty

Thursday, May 1st, 2008

Well, Microsoft has finally come clean about the real motivation behind Vista's User Account Control feature. As Tom Espiner's reports from the recent RSA Conference in San Francisco, Microsoft UAC Program Manager David Cross admits that UAC was designed to annoy users. Espiner quotes Cross telling the security-conference audience that negative ...

Microsoft offers assistance to combat mass SQL injection

Monday, April 28th, 2008

Microsoft has provided security advice to web developers using its products after many such sites were compromised. Last week, hundreds of thousands of web pages were infected with a malicious iframe which tries to infect visitors with a trojan. Many high profile sites including the United Nations (un.org), the UK ...

Reverse-Engineering Exploits from Patches

Wednesday, April 23rd, 2008

The automatic patch-based exploit generation problem is: given a program P and a patched version of the program P', automatically generate an exploit for the potentially unknown vulnerability present in P but fixed in P'. In this paper, we propose techniques for automatic patch-based exploit generation, and show that our ...