Microsoft to Release !exploitable Crash Analyzer as an Open Source Tool and more … - Ruud de Jonge

Ruud de Jonge

over Microsoft Platform en Security ontwikkelingen

Microsoft to Release !exploitable Crash Analyzer as an Open Source Tool and more …

image

On Friday, March 20, Microsoft’s Security Science team will release the!exploitable Crash Analyzer tool as an open source tool on CodePlex at CanSecWest in Vancouver, British Columbia. The tool will be available as a free download on the Microsoft Security Engineering Center (MSEC) Web site, http://www.microsoft.com/security/msec, later that day.

!exploitable Crash Analyzer is a Windows Debugger extension that determines the uniqueness of crashes produced during development and testing, identifying those that have security implications and how exploitable they are. For more information, including a fact sheet on the tool, please visit Press Pass, http://www.microsoft.com/presspass/newsroom/security/default.mspx.

The Security Science group is part of Microsoft’s Trustworthy Computing organization, focused on protecting its customers and the industry by improving the security of Microsoft products, services and platforms through applied security research. This group of elite researchers and developers tracks and provides early warnings for new exploits, develops more effective ways to find vulnerabilities, and using its internal research, integrates innovative exploit mitigation techniques and tools to Microsoft products and in some cases, shares those tools with the broader industry.

Additionally, Trustworthy Computing will give two other presentations at the event focused on the Security Science team’s exploit mitigations, how they have been employed, why they were chosen, and how Microsoft systematically thinks about mitigations coverage.

About Enhanced GS

Enhanced GS is a mitigation designed to make it harder to exploit security vulnerabilities when they occur.

/GS (pronounced “slash GS”) is the current buffer security check feature of the Microsoft Visual Studio C++ compiler. It detects common classes of buffer overruns by injecting security checks into code compiled with this feature. Enhanced GS is the enhanced version of /GS that improves stack buffer overflow mitigation by analyzing and helping protect more functions.

Enhanced GS does deeper function analysis than /GS. Enhanced GS more accurately identifies potential hazards, thus making vulnerabilities more difficult to exploit when they occur. This enhancement enables protection to be deployed in the right places and reduces redundant protections.

Tool Release

Microsoft Corp. plans to release Enhanced GS to developers in Visual Studio 2010. In addition, Enhanced GS will be included in the Security Development Lifecycle after it is released with Visual Studio 2010.

Given that Enhanced GS is an update of the current compiler, anyone who receives the compiler update will get the new version, Enhanced GS.

Benefits

Microsoft and third-party developers will use this built-in mitigation whenever they use Visual Studio 2010. Customers will benefit from more secure products. Products built with the new Enhanced GS will be less vulnerable to buffer overflows as there will be fewer exploitable stack overflow vulnerabilities.

Microsoft plans to release this mitigation with Visual Studio 2010, which means customers will see the benefit when the next wave of products comes out after Visual Studio 2010 is released.

Posted: Mar 19 2009, 07:16 PM door Ruud de Jonge | met 5 comment(s)
Opgeslagen onder:

Commentaar:

Pieter zei:

Ik heb IE8 getest, maar zeer traag, het openen ervan duurde 8 seconden, mij iets te lang.

Nu heb ik hem weer van de pc afgegooid, terug naar 7 dus maar nu opent hij iedere keer deze pagina runonce.msn.com/runonce3.aspx terwijl toch echt me start pagina google.nl moet zijn. Verder heeft hij nog meer instellingen door elkaar gegooid maar daar is mee te leven, maar dit is wel heel lastig.

Hoe los ik dit op?

Helaas bied Microsoft geen ondersteuning, ja dat doen ze wel maar dan moet je eerst 72 euro betalen. Zou prettig zijn als ik antwoord zou krijgen.

# March 20, 2009 3:22 AM

Microsoft ayuda a los desarrolladores a comprobar la Seguridad de sus aplicaciones « zei:

Pingback from  Microsoft ayuda a los desarrolladores a comprobar la Seguridad de sus aplicaciones «

# March 20, 2009 2:14 PM

Quand je vous dis que Microsoft devient un ??diteur open source | Philippe.Scoffoni.Net zei:

Pingback from  Quand je vous dis que Microsoft devient un ??diteur open source  | Philippe.Scoffoni.Net

# March 20, 2009 10:39 PM

Microsoft to Release !exploitable Crash Analyzer as an Open Source Tool and more ??? « Dotsecure Information Security zei:

Pingback from  Microsoft to Release !exploitable Crash Analyzer as an Open Source Tool and more ??? «  Dotsecure Information Security

# March 24, 2009 10:08 AM

Sjef van Kuijk zei:

Hallo Pieter.

Ik las je bericht en dacht laat ik je helpen ermee.

Het betreft de runonce.msn.com/runonce3.aspx.

Ik heb IE8 getest, maar zeer traag, het openen ervan duurde 8 seconden, mij iets te lang.

Nou heel simpel, je opent de explorer, ga naar extra,Internet opties. Nieuwe pop laat de setup zien zoals je weet.

Ga naar Instellingen tablad, stellingen. Daar zie je enkele opties voor het browsen met tabbladen. Daar staat een vinkje in, de tweede geen vinkje, 3e en 4e weer wel, 5e geen, 6e weer wel, maar nu komt het, Het volgende openen als er een nieuwe tabblad wordt geopend: druk op dat zwartepijltje, selecteer de laatste optie, UW EERSTE STARTPAGINA.

Daarna de onderste Pop-ups invullen, de laatste Koppelingen, de 2e invullen, je probleem is hiermee verholpen.

Succes met het aanpassen van je probleem.

Groeten Sjef van Kuijk.

# March 27, 2009 3:33 AM
Wat denkt u?

(Verplicht) 

(Verplicht) 

(Optioneel)

(Verplicht) 
CaptchaCube Vraag:


Antwoord: