Featured Products
Product Details
 
 
 
Customer Comments
800-672-4806 | 425-672-4806 | sales@ccscentral.com
User Guest (38.107.179.214)

Them Hackers Keep Getting Smarter

E-mail Print

Via The Houston Chronicle

A group of computer-security researchers may have just made all of your Windows antivirus software obsolete.


Matousec.com issued an advisory last week that chronicles a process by which malware could circumvent just about every security product out there. We're talking McAfee, Norton, BitDefender ... the works. The researchers devised a mock-up piece of malicious software that morphs itself at exactly the right time. Just after an antivirus program scans an excerpt of code, the malware can swap that benign code for malicious code before it's executed.

It's being called an "argument-switch attack." From a good description by The Register:

The exploit has to be timed just right so the benign code isn't switched too soon or too late. But for systems running on multi-core processors, matousec's "argument-switch" attack is fairly reliable because one thread is often unable to keep track of other simultaneously running threads. As a result, the vast majority of malware protection offered for Windows PCs can be tricked into allowing malicious code that under normal conditions would be blocked. ...

Still, the exploit has its limitations. It requires a large amount of code to be loaded onto the targeted machine, making it impractical for shellcode-based attacks or attacks that rely on speed and stealth. It can also be carried out only when an attacker already has the ability to run a binary on the targeted PC.

The argument-switch attack exploits the System Service Descriptor Table (SSDT) used by antivirus software – well, any software – which provides a "hook" to the Windows kernel. If you're technical enough to know what that means, there's plenty of more in-depth information in a report by Matousec.

"The research was done on Windows XP Service Pack 3 and Windows Vista Service Pack 1 on 32-bit hardware," the report states. "However, it is valid for all Windows versions including Windows 7. Even the 64-bit platform is not a limitation for the attack."

Lucian Constantin, of Softpedia, notes on a company blog that the underlying vulnerability has been known for years. And there have been no widespread exploits using the tactic.

"On the other hand, it is also true that multi-core processors, which drastically increase the success rate of this attack, have since become widespread in desktop computers," Constantin wrote. "Nevertheless, from information we received in confidence, some antivirus vendors were already planning to stop using SSDT hooks in the next version of their products, since before this research came out."

So, maybe we'll all be safe. I guess we'll see how the security companies play this one.

Once again, being vigilant about what sites you surf, and what emails you open will usually prevent an infection in the first place.  It is also important to scan your machine with anti-virus AND anti-malware software at least once a week.

If you have any further questions, please contact the CCS Retail Systems Support Department @ 800-672-4806 or email us.  We will be more than happy to answer and resolve your concerns

-Bryan alt

 

Last Updated on Monday, 10 May 2010 19:30  
Privacy Policy | CCS Sales | CCS Support | CCS Training | CCS Administration | Author Help | CCS Webmaster | Site Map

© Copyright 2012, CCS Retail Systems, Inc. All Rights Reserved.

Customer Connect Marketing

Customer Connect Video and Details The Only Email Marketing Tool Built for Retailers

Customer Connect (CC) is Loaded With The Features And Functionality Needed For RetailersFully integrated with CounterPoint V7 and CounterPoint SQL, Customer Connect gives you the data needed to effectively connect with your customers, drive sales and increase customer loyalty.

New CustomerConnect Features!

Subscribe to CCS Specials Newsletter.  To unsubscribe use the link at the bottom of a newsletter. CCS Newsletter Sign-up

Visit CCS CustomerConnect eNews Archive CCS CustomerConnect eNews Archive

Quick Menu

 

 

 

 

Recovery Act Tax Deductions

"American Recovery and Reinvestment Act has officially extended the Section 179 Tax Deduction increases for the 2011 Tax Year"

Section 179 can be extremely profitable to you, so it is to your benefit to learn as much as possible. To begin, you probably have a lot of questions regarding Section 179. Follow the links below to get the details on this opportunity:  more ...

 Radiant CounterPoint POS

Radiant Introduces NEW CounterPoint POS Releases

This New 8.3.9 Release of CounterPoint was developed to give retailers New Features and Functions that increase profitability, and ensure a rapid return on investment.

Contact your CCS Sales Consultant to discuss all the new features and functions included.  Ask how they will Keep the Checkouts moving, the Inventory Optimized, and the Back-office Managed. Here are just a few of CounterPoint 8.3.9’s enhancements:  

♦ Registry/Wish List ♦ Message Center
♦ Margin Driven Pricing ♦ Miscellaneous Kits
♦ Tag-Along Kits ♦ Scrap Items
♦ Inactive Items ♦ Discount Overrides
♦ Item Zoom ♦ Forecasted Advices
♦ Enhanced Advices ♦ Work Center
♦ PCI DSS Passwords ♦ Enhanced CC Security

CPSQL 8.4.0 is on its way. Check out What's Coming with the link below!

CPSQL 8.4.0  | CP V7.5.19  | Product News | POS Stations

Why Choose CPSQL?

We have selected two dozen Recent New Retail CounterPoint SQL POS Customers to Profile for you. 

We suspect that you may have Needs Similar to theirs.  See Why these Retailers chose CPSQL and What they Found to be the Benefits.   more ...

Is Your System Healthy?

Great Deals!  New and Refurbished Systems.  Netbooks, Notebooks, Desktops, Servers, Storage Systems, Retail Devices.  Configure your own Systems for us to install.  more ...

Topic Cloud

GeoIP Location

Bookmark Us

Add to: JBookmarks Add to: Facebook Add to: Buzka Add to: Windows Live Add to: Ximmy Add to: Bookmarks.cc Add to: Linkarena Add to: Digg Add to: Del.icoi.us Add to: Reddit Add to: Jumptags Add to: Upchuckr Add to: StumbleUpon Add to: Slashdot Add to: Netscape Add to: Furl Add to: Yahoo Add to: Blogmarks Add to: Diigo Add to: Technorati Add to: Newsvine Add to: Blinkbits Add to: Ma.Gnolia Add to: Smarking Add to: Spurl Add to: Google Add to: Blinklist Information

Spam Free



Translate Page




Bryan's Blog Newsfeed Subscribe to FeedBurner

Products and Services

 
Product Details
 
 
 

CCS Customer Comments

Customer Referrals

CCS offers rewards for each new, verified Prospect referral. We encourage you to think of the value that CounterPoint has added to your business and share that with others who will also benefit.

Submit a ReferralSubmitReferral

Get Involved In Our Site!

Become an Author.We encourage our customers, suppliers, and friends to participate in our site.  See the Visitor Services pages for details.