New code injection exposes all versions of Windows to cyberattack.

    New code injection exposes all versions of Windows to cyberattack.


    Posted: 29 Oct 2016
    New code injection exposes all versions of Windows to cyberattack.



    Researchers have disclosed a fresh attack against Microsoft's Windows operating system which can be used to inject malicious code and compromise user PCs.


    On October 27, cybersecurity company enSilo's research team disclosed a practice called "AtomBombing" that can be launched against every version of Windows to bypass current security solutions which protect such systems from malware infections.


    The technique is dubbed AtomBombing as it relies on underlying Windows atom tables to exploit a system. Atom tables are used to store strings and identifiers by Windows which support other application functions.




    More info
    Posted By: groze
    29 Oct 2016



  1. Posts : 1,167
    W10 32 bit, XUbuntu 18.xx 64 bit
       #1

    What I don't understand is how it can bypass security software according to the zdnet article?
      My Computer


  2. Posts : 4,049
    W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
       #2

    groze said:
    What I don't understand is how it can bypass security software according to the zdnet article?
    As far as I can tell this seems to be saying that:

    • The hacker injects malicious code into this table
    • The user asks a program to perform some action (which will access the corrupted code in the table)
    • The program asks Windows to execute the action
    • The user's AV program determines that Windows has requested this (malicious) action and therefore ignores it
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 11:01.
Find Us