nForcersHQ
 
nForcersHQForumDistributed ComputingFAQLog inRegisterSearch
 
nForcersHQ

New form of attacking encryptation...
Post new topic Reply to topic    nForcersHQ.com Forum Index » Software
Login to view full posting options
Author Message
Google
AdSense

Back to top  
impar
PC Gamer
Moderator
Moderator

Joined: 21 Mar 2003
Posts: 17803
Location: Portugal

PostPosted: Fri Feb 22, 2008 12:12 pm    Post subject: New form of attacking encryptation...

Greetings!

Cold boot disk encryption attack is shockingly effective

Since the encryption key for systems like BitLocker and FileVault lives in RAM, all an attacker has to do to get it is cool the RAM modules with the air duster held upside down, yank the DIMM, and insert it into another machine, where it can then be read to access the key. Of course, this assumes that you've already typed in your password, but check the video after the break to see how long bits in RAM stay written -- even if you've turned off your computer, there's a chance the key can still be read.


Shocked
Back to top
impar
PC Gamer
Moderator
Moderator

Joined: 21 Mar 2003
Posts: 17803
Location: Portugal

PostPosted: Tue Mar 04, 2008 4:04 pm    Post subject:

Greetings!

Bootable flash key makes disk encryption attacks super-simple

... you remember that disk encryption attack that involved cooling off your target's RAM and yanking it to get a bitdump before the contents faded? Well, it looks like things just got a lot simpler for would-be attackers -- check out this USB flash key designed by security researcher Robert Wesley McGrew, which can boot your machine and dump the RAM to itself without altering its contents. That means you no longer need to actually pull the DIMMs or carry around an air duster; all an attacker needs is enough time to reboot your machine and copy the contents of your RAM.
Back to top
impar
PC Gamer
Moderator
Moderator

Joined: 21 Mar 2003
Posts: 17803
Location: Portugal

PostPosted: Wed Mar 05, 2008 12:33 pm    Post subject:

Greetings!

Windows passwords easily bypassed over Firewire
...
Unlike those disk encryption attacks we saw that required a reboot, Boileu's attack works while the target computer is running, tricking Windows into allowing full write access to RAM and then corrupting the password protection code. That's a little scary -- but other researchers say that it's not a traditional vulnerability, since direct memory access is a feature of Firewire.
...
Update: Apparently this has been demonstrated on OS X as well -- it looks like Firewire's direct memory access is the common vector here.



Moved to Software.
Back to top
Seawolf
Ultra nForced
Ultra nForced

Joined: 23 Jun 2002
Posts: 14874
Location: In circles

PostPosted: Wed Mar 05, 2008 12:43 pm    Post subject:

Hmm, don't think it'd work on Vista x64 what with ASLR.
Back to top
bardu
nForced
nForced

Joined: 07 Dec 2005
Posts: 1333
Location: ROMANIA

PostPosted: Thu Mar 06, 2008 7:01 am    Post subject:

Shocked .... those Linux things are amazing! I guess a PC is truly secure when it's well placed in a bank like vault!
Back to top
Seawolf
Ultra nForced
Ultra nForced

Joined: 23 Jun 2002
Posts: 14874
Location: In circles

PostPosted: Thu Mar 06, 2008 9:49 am    Post subject:

Indeed, that's been true for a long time. Most people aren't going to be too worried about an attack that needs physical access.
Back to top
impar
PC Gamer
Moderator
Moderator

Joined: 21 Mar 2003
Posts: 17803
Location: Portugal

PostPosted: Tue Jul 22, 2008 10:11 am    Post subject:

Greetings!

Source code released for canned-air FileVault/BitLocker hack

The same group of researchers that published a paper last February detailing how their team hacked into and recovered data from a group of supposedly secure laptops have now released the source code to the programs they used in their "cold boot" experiment. Such software could be useful to any law enforcement agency looking to take advantage of the group's research, as well as to any security vendor attempting to plug the hole.
Back to top
Google
AdSense
Google
Back to top  
Display posts from previous:   
Post new topic   Reply to topic    nForcersHQ.com Forum Index » Software
All times are GMT Page 1 of 1


ToS | Privacy | Forum Rules | Contact | Advertise on this site
NVIDIA, the NVIDIA logo, NVIDIA nForce and all of the NVIDIA nForce product logos are trademarks of NVIDIA Corporation
nPowered by phpBB © 2007 phpBB Group  All rights reserved © 2001-2008 Michael Day nFHQ nForcersHQ.com | Fluffy-Gear.com
nForcersHQ supporters: Impar, wardog, MiniMax, envoid, jasonh, Krips, VAIOMAN, Zetro, sensai, me&er, RElliott, ScottRempel, JHogarth, IcemanIX, Etraman, KA, Tabajara, Xiomberg, ruddywarrior, hookahmike, MMoore, RHodgson, RGilson, powerarmour, Sepal, RRavat, DigitalRuin, HammerheadTech, Bane, DHunt, Fat Jez, baikal, Jumpin' Jon, MGadzikowski, JBishop, RDeBok, JDavies, HDHyland, TMorris