<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Inquisitr &#187; exploit</title>
	<atom:link href="http://www.inquisitr.com/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.inquisitr.com</link>
	<description>The Better Mix</description>
	<lastBuildDate>Tue, 14 Feb 2012 18:58:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Windows 8 Bootkit Exploit Already Discovered [Video Demonstration]</title>
		<link>http://www.inquisitr.com/162698/windows-8-bootkit-exploit-already-discovered-video-demonstration/</link>
		<comments>http://www.inquisitr.com/162698/windows-8-bootkit-exploit-already-discovered-video-demonstration/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 20:32:48 +0000</pubDate>
		<dc:creator>James Johnson</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Bootkit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/?p=162698</guid>
		<description><![CDATA[<br />Security researcher Peter Kleissner has managed to bypass User Account Control on Windows 8 through the use of a small 14KB piece of code. According to ZDNET Peter&#8217;s hack is believed to be the first proof-of-concept that has found a vulnerability in Microsoft&#8217;s new operating system which will launch in 2012. After the exploit has been launched [...]<p><a href="http://www.inquisitr.com/162698/windows-8-bootkit-exploit-already-discovered-video-demonstration/">Windows 8 Bootkit Exploit Already Discovered [Video Demonstration]</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-162699" title="Windows 8" src="http://www.inquisitr.com/wp-content/2011/11/Windows-8.jpg" alt="Windows 8" width="451" height="292" /></p>
<p>Security researcher Peter Kleissner has managed to bypass User Account Control on Windows 8 through the use of a small 14KB piece of code.</p>
<p>According to <a href="http://www.zdnet.com/blog/hardware/windows-8-bootkit-demo/16572" rel="nofollow">ZDNET</a> Peter&#8217;s hack is believed to be the first proof-of-concept that has found a vulnerability in Microsoft&#8217;s new operating system which will launch in 2012.</p>
<p>After the exploit has been launched the OS operates under the SYSTEM account which then lets a hacker run a command prompt where they can defeat the User Account Control by avoiding the user prompt.</p>
<p>The <a title="Microsoft To Roll Out Office 15 Beta On January 15" href="http://www.inquisitr.com/162375/microsoft-to-roll-out-office-15-beta-on-january-15/">Windows 8 OS</a> is currently in Beta testing and the exploit will likely be fixed ahead of shipping however the small size of the code and the ease for which it was executed still deal a small humiliating blow to Microsoft as the company continues to emphasize their platforms stronger security standards via Windows Defender improvements.</p>
<p>Included with the new system is a real-time detection and protection suite along with a SmartScreen filtering system for Windows 8 and security improvements to Internet Explroer.</p>
<p>Here&#8217;s Peter Kleissner showing off the hack:</p>

<!-- powered by Iframe plugin ver.2.1 (wordpress.org/extend/plugins/iframe/) -->
<iframe src="http://player.vimeo.com/video/32666961?title=0&amp;amp;byline=0&amp;amp;portrait=0" width="400" height="300" scrolling="no" class="iframe-class" frameborder="0"></iframe>
<p>[via <a title="Microsoft Windows 8" href="http://www.electronista.com/articles/11/11/25/peter.kleissner.shows.14kb.bootkit.for.windows.8/">Electronisa</a>]</p>
<p>&nbsp;</p>
<p><a href="http://www.inquisitr.com/162698/windows-8-bootkit-exploit-already-discovered-video-demonstration/">Windows 8 Bootkit Exploit Already Discovered [Video Demonstration]</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/162698/windows-8-bootkit-exploit-already-discovered-video-demonstration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/2011/11/Windows-8-100x100.jpg" />
		<media:content url="http://www.inquisitr.com/wp-content/2011/11/Windows-8.jpg" medium="image">
			<media:title type="html">Windows 8</media:title>
			<media:thumbnail url="http://www.inquisitr.com/wp-content/2011/11/Windows-8-100x100.jpg" />
		</media:content>
	</item>
		<item>
		<title>Apple Safari is a hacker&#8217;s info harvesting dream</title>
		<link>http://www.inquisitr.com/80019/apple-safari-is-a-hackers-info-harvesting-dream/</link>
		<comments>http://www.inquisitr.com/80019/apple-safari-is-a-hackers-info-harvesting-dream/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 18:18:22 +0000</pubDate>
		<dc:creator>Steven Hodson</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Browser]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[safari]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/?p=80019</guid>
		<description><![CDATA[<br />This apparently applies to Safari on Macs and no word yet if it applies to the Windows version of Apple&#8217;s browser but the folks over at 9 to 5 Mac have posted an alarming notice to all Safari users to immediately disable the browsers autofill feature. It seems that one of the autofill features allows [...]<p><a href="http://www.inquisitr.com/80019/apple-safari-is-a-hackers-info-harvesting-dream/">Apple Safari is a hacker&#8217;s info harvesting dream</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
			<content:encoded><![CDATA[<p>This apparently applies to Safari on Macs and no word yet if it applies to the Windows version of Apple&#8217;s browser but the folks over at 9 to 5 Mac have posted an alarming notice to all Safari users to immediately disable the browsers autofill feature.</p>
<p><img class="aligncenter size-full wp-image-80020" title="prefs" src="http://images.inquisitr.com/wp-content/2010/07/prefs-e1279822660649.png" alt="" width="550" height="157" /></p>
<p>It seems that one of the autofill features allows you to have web forms automatically filled, even if you have never been to the site before, by pulling in your information from your Address Book card. The danger, as outlined by Jeremiah Grossman using a very simple exploit, is that malicious sites could create hidden dynamic form text fields which would then be populated with your information using Javascript A-Z keystrokes.</p>
<blockquote><p>As  shown in the <a href="http://ha.ckers.org/weird/safari_autofill.html">proof-of-concept code</a> (graciously hosted by <a href="http://ha.ckers.org/">Robert &#8220;RSnake&#8221; Hansen</a>), the entire process takes  mere seconds and represents a major breach in online privacy. This attack could  be further leveraged in multistage attacks including email spam, (spear)  phishing, stalking, and even blackmail if a user is de-anonymized while visiting  objectionable online material.</p></blockquote>
<p>Sometimes the best hacks are the simplest ones but it also goes to show that security problems are just the providence of any one tech company.</p>
<p><em>image courtesy of 9 to 5 Mac</em></p>
<p><a href="http://www.inquisitr.com/80019/apple-safari-is-a-hackers-info-harvesting-dream/">Apple Safari is a hacker&#8217;s info harvesting dream</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/80019/apple-safari-is-a-hackers-info-harvesting-dream/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/2010/07/prefs-100x100.png" />
		<media:content url="http://www.inquisitr.com/wp-content/2010/07/prefs-e1279822660649.png" medium="image">
			<media:title type="html">prefs</media:title>
			<media:thumbnail url="http://www.inquisitr.com/wp-content/2010/07/prefs-100x100.png" />
		</media:content>
	</item>
		<item>
		<title>CPU poisoning affects Intel systems</title>
		<link>http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/</link>
		<comments>http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 17:38:38 +0000</pubDate>
		<dc:creator>Steven Hodson</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[CPU]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/</guid>
		<description><![CDATA[<br />Researchers at Invisible Things Lab presented information at the CanSecWest conference on Thursday in Vancouver about a security exploit that could comprise computers running on Intel processors. The exploit involves the poisoning of of the cache of a CPU operating in System Management Mode (SMM). They also noted that this was the third such types [...]<p><a href="http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/">CPU poisoning affects Intel systems</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
<br /><br /><br />]]></description>
			<content:encoded><![CDATA[<p><center><img title="poison" border="0" alt="poison" src="http://www.inquisitr.com/wp-content/poison.jpg" width="379" height="284" /> </center>
<p>Researchers at Invisible Things Lab presented information at the CanSecWest conference on Thursday in Vancouver about a security exploit that could comprise computers running on Intel processors. The exploit involves the poisoning of of the cache of a CPU operating in System Management Mode (SMM). They also noted that this was the third such types of security exploits that the team had found affecting Intel based computers in the last ten months.</p>
<p>The SMM exploit works by poisoning the chip’s cache memory which would allow for forced access to SMM, one of the most privileged CPU modes on x86 architectures. Even operating systems can’t access SMM – the mode that handles certain errors, power management and other features.</p>
<blockquote><p>The potential consequence of attacks on SMM might include SMM rootkits, hypervisor compromises, or OS kernel protection bypassing, they said.</p>
<p>Intel has been working on a solution to prevent caching attacks on SMM memory, and a spokesperson has said that many new systems are protected against the exploit. But, writing in their paper, Rutkowska and Wojtczuk said: “Some of Intel&#8217;s recent motherboards, like the popular DQ35, are still vulnerable to the attack. Additionally, the workarounds that Intel has mentioned to us are not yet officially documented.”</p>
<p>Source: SC Magazine &#8211; <a href="http://www.scmagazineus.com/Intel-CPU-exploit-threatens-PCs-worldwide/article/129194/">Intel CPU exploit threatens PCs worldwide</a></p>
</blockquote>
<p>Time to bloated Norton solution in 3 …. 2 …. 1…..</p>
<p><a href="http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/">CPU poisoning affects Intel systems</a> is a post from: <a href="http://www.inquisitr.com">The Inquisitr</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.inquisitr.com/29793/cpu-poisoning-affect-intel-systems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:thumbnail url="http://www.inquisitr.com/wp-content/poison.jpg" />
		<media:content url="http://www.inquisitr.com/wp-content/poison.jpg" medium="image">
			<media:title type="html">poison</media:title>
		</media:content>
	</item>
	</channel>
</rss>

