<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; ampersand</title> <atom:link href="http://m32consulting.com/tag/ampersand/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Sun, 22 Jan 2012 23:37:02 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>Critical Microsoft Vista/2008/Windows 7 Zero-day Remote BSOD Found</title><link>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found</link> <comments>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/#comments</comments> <pubDate>Wed, 09 Sep 2009 00:24:06 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Corporate]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[ampersand]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[blue screen of death]]></category> <category><![CDATA[BSOD]]></category> <category><![CDATA[Laurent Gaffié]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft vista]]></category> <category><![CDATA[microsoft windows vista]]></category> <category><![CDATA[OOB]]></category> <category><![CDATA[process id]]></category> <category><![CDATA[proof of concept]]></category> <category><![CDATA[SMB]]></category> <category><![CDATA[throwback]]></category> <category><![CDATA[versions of windows vista]]></category> <category><![CDATA[vulnerability]]></category> <category><![CDATA[zero day]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=41</guid> <description><![CDATA[Remember back in the days of Windows 95 when someone could use the OOB attack to remotely BSOD a PC? Well now you can relive your youth with a classic throwback from Microsoft! Windows Vista, 2008, and 2007 of all variants all have a similar vulnerability that allows a remote attacker take your machine down [...]]]></description> <content:encoded><![CDATA[<p>Remember back in the days of Windows 95 when someone could use the OOB attack to remotely BSOD a PC? Well now you can relive your youth with a classic throwback from Microsoft! Windows Vista, 2008, and 2007 of all variants all have a similar vulnerability that allows a remote attacker take your machine down with a simple ampersand. Leave it up to Microsoft to do it all again more than a decade later.</p><p>The SMB 2.0 driver in x86 and x64 versions of Windows Vista, Server 2008, and Windows 7 are all one in the same. When sent the &#8220;&amp;&#8221; character in the &#8220;Process ID High&#8221; SMB header, the process pagefaults and brings us the beloved Blue Screen of Death we&#8217;ve all come to know and love.</p><p><a
href="http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html" target="_blank">Credit goes to Laurent Gaffié and you can find the Proof-of-Concept on his blog.</a></p>Tags: <a
href="http://m32consulting.com/tag/ampersand/" title="ampersand" rel="tag">ampersand</a>, <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/attacker/" title="attacker" rel="tag">attacker</a>, <a
href="http://m32consulting.com/tag/blue-screen-of-death/" title="blue screen of death" rel="tag">blue screen of death</a>, <a
href="http://m32consulting.com/tag/bsod/" title="BSOD" rel="tag">BSOD</a>, <a
href="http://m32consulting.com/tag/laurent-gaffie/" title="Laurent Gaffié" rel="tag">Laurent Gaffié</a>, <a
href="http://m32consulting.com/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a
href="http://m32consulting.com/tag/microsoft-vista/" title="microsoft vista" rel="tag">microsoft vista</a>, <a
href="http://m32consulting.com/tag/microsoft-windows-vista/" title="microsoft windows vista" rel="tag">microsoft windows vista</a>, <a
href="http://m32consulting.com/tag/oob/" title="OOB" rel="tag">OOB</a>, <a
href="http://m32consulting.com/tag/process-id/" title="process id" rel="tag">process id</a>, <a
href="http://m32consulting.com/tag/proof-of-concept/" title="proof of concept" rel="tag">proof of concept</a>, <a
href="http://m32consulting.com/tag/smb/" title="SMB" rel="tag">SMB</a>, <a
href="http://m32consulting.com/tag/throwback/" title="throwback" rel="tag">throwback</a>, <a
href="http://m32consulting.com/tag/versions-of-windows-vista/" title="versions of windows vista" rel="tag">versions of windows vista</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a
href="http://m32consulting.com/tag/zero-day/" title="zero day" rel="tag">zero day</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/09/critical-microsoft-vista2008windows-7-zero-day-remote-bsod-found/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 4/16 queries in 0.019 seconds using disk: basic
Object Caching 970/995 objects using disk: basic

Served from: m32consulting.com @ 2012-02-11 14:55:31 -->
