Your Ad Here
Go Back   Unlimited downloads forum > The Lounge > General Talk

Reply
 
LinkBack Thread Tools Display Modes

 Vista Can Be Taken Down by an Animated Cursor!
Old 04-06-2007, 12:00 PM   #1 (permalink)
Senior Member
 
eXtreme's Avatar
 
eXtreme is offline
Join Date: Nov 2006
Age: 28
Posts: 278
eXtreme is on a distinguished road
Rep Power: 3
Vista Can Be Taken Down by an Animated Cursor!

In what could be the most embarrassing exploit to impact Windows Vista since its commercial launch in January, security engineers at McAfee's Avert Labs confirmed today - and posted the video to prove - that the operating system can be caused to enter an interminable crash-restart-crash loop, by means of a buffer overflow triggered by nothing more than a malformed animated cursor file.


It isn't even a new exploit, as researchers with eEye discovered in January 2005. At that time, Microsoft acknowledged it affected versions of the operating system from the first edition of Windows 98 through to early releases of Windows XP, though it stated at the time XP SP1 was unaffected.

But apparently after researching field reports of limited attacks, Avert Labs discovered an apparently similar exploit using .ANI files impacts XP SP2 and Vista, as well as Windows 2000 SP4 and versions of Windows Server 2003 from the initial release through to SP1. Avert Labs stated XP SP1 and versions since were unaffected, though Microsoft warned the exploit does affect XP SP2.

If both firms' accounts are correct, Microsoft may have fixed the problem with XP SP1 in 2005, and inadvertently un-fixed it sometime afterward.

Avert Labs' video of the incident, posted to YouTube, shows a Vista system wherein the test file apparently trying to load the custom animated cursor. When the operating system detects a crash, it first tries to save vital data prior to a restart sequence - one of Vista's newer features. It then informs the user that Windows Explorer has crashed.

But in trying to restart Explorer, the restarting crashes itself, sending Vista into a tailspin from which the only escape appears to be the off button.

The mouse input routines in Windows are designed with the intention of being relatively failsafe. That's why when the system appears to hang, you can often still move your mouse pointer. As I've personally witnessed on many occasions with Windows XP, it's possible for a smaller OEM's mouse driver - often an unsigned one - to trigger a similar tailspin loop that crashes Windows Explorer repeatedly. In Windows, a lot depends on the mouse pointer's very existence.

So if a customization feature can impact the mouse pointer's ability to function, the integrity of the entire system can be jeopardized. With my own systems, drivers and services that are unfriendly to one another - such as Stardock's CursorXP animation program trying to co-exist with a Synaptics Pointing Device driver on a notebook with ATI Mobility Radeon 9600 graphics - can trigger an Explorer tailspin.

What I'm calling the "tailspin" is nothing new. What is very disturbing about this revelation, however, is that it can be triggered by nothing more than Microsoft's own operating system software and processes.

McAfee reports this exploit is being utilized in the wild, and Microsoft today issued its boilerplate language warning users not to open e-mail attachments they don't recognize.



ROFL... good1 M$!
__________________
Quote:
Don't forget to 'Code' your links, live links are NOT allowed:
[SIGPIC][/SIGPIC]







...If you like my posts, please press the red +Rep and Thanks buttons just below... Thank you!

  Reply With Quote

 
Old 04-13-2007, 02:02 AM   #2 (permalink)
Junior Member
 
spongeduckie's Avatar
 
spongeduckie is offline
Join Date: Apr 2007
Age: 26
Posts: 26
spongeduckie is on a distinguished road
Rep Power: 0
Really?!?!?!?!?
Wow that just sucks.
__________________
"I Need Input"
  Reply With Quote

 
Old 04-13-2007, 10:05 AM   #3 (permalink)
Member
 
Revolutions's Avatar
 
Revolutions is offline
Join Date: Apr 2007
Age: 28
Posts: 44
Revolutions is on a distinguished road
Rep Power: 0
LOLL microsoft always gets done over by their shit os's
  Reply With Quote

 
Old 04-13-2007, 06:16 PM   #4 (permalink)
Junior Member
 
LaHrr.S's Avatar
 
LaHrr.S is offline
Join Date: Apr 2007
Age: 19
Posts: 9
LaHrr.S is on a distinguished road
Rep Power: 0
Quote:
Originally Posted by Revolutions View Post
LOLL microsoft always gets done over by their shit os's
Let me guess, you use Windows?
  Reply With Quote

 
Old 04-13-2007, 06:23 PM   #5 (permalink)
Senior Member
 
Harut's Avatar
 
Harut is offline
Join Date: Dec 2006
Location: california
Posts: 327
Harut is on a distinguished road
Rep Power: 3
dam i have vista
  Reply With Quote
Reply
Tags: , , , ,



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
How to Make an Animated Movie sukhman21 Aniboom 0 01-02-2009 02:25 PM
25 Windows Vista Themes and 48 Vista Wallpapers sukhman21 Applications 7 02-22-2007 09:54 AM
Animator VS Animated II AdDd45 Funny/fight/other videos 0 11-24-2006 12:26 AM
Animator VS Animated. Dem Pyros Funny/fight/other videos 6 11-24-2006 12:14 AM



All times are GMT -6. The time now is 08:39 PM.


vBulletin skins developed by: eXtremepixels
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0


[Output: 57.64 Kb. compressed to 53.90 Kb. by saving 3.74 Kb. (6.49%)]