漏洞信息详情
IEEE1394规格 权限绕过泄露漏洞
漏洞简介
IEEE1394规格中存在设计错误,可物理访问设备的攻击者使用修改后的FireWire/IEEE 1394客户端,然后绕过通常需要较高物理访问exploit权限的专门限制,便可读写敏感存储区。
漏洞公告
参考网址
来源: XF
名称: firewire-ieee1394-interface-installed(18041)
链接:http://xforce.iss.net/xforce/xfdb/18041
来源: MISC
链接:http://www.theage.com.au/news/security/hack-into-a-windows-pc-no-password-needed/2008/03/04/1204402423638.html
来源: BUGTRAQ
名称: 20080310 Re: [Full-disclosure] Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489342/100/0/threaded
来源: BUGTRAQ
名称: 20080309 Re: Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489335/100/0/threaded
来源: BUGTRAQ
名称: 20080310 RE: [Full-disclosure] Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489330/100/0/threaded
来源: BUGTRAQ
名称: 20080309 Re: [Full-disclosure] Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489322/100/0/threaded
来源: BUGTRAQ
名称: 20080305 RE: Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489189/100/0/threaded
来源: BUGTRAQ
名称: 20080305 Re: Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489175/100/0/threaded
来源: BUGTRAQ
名称: 20080305 Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489163/100/0/threaded
来源: MISC
链接:http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.pdf
来源: MISC
名称: http://storm.net.nz/static/files/ab_firewire_rux2k6-final.pdf
链接:http://storm.net.nz/static/files/ab_firewire_rux2k6-final.pdf
来源: MISC
链接:http://storm.net.nz/projects/16
来源: MISC
链接:http://pacsec.jp/advisories.html
来源: MISC
链接:http://md.hudora.de/presentations/firewire/2005-firewire-cansecwest.pdf
来源: BUGTRAQ
名称: 20041026 pacsec.jp advisory: Firewire/IEEE 1394 Considered Harmful to Physical Security
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109881362530790&w=2
来源: MISC
链接:http://it.slashdot.org/article.pl?sid=08/03/04/1258210
来源: BUGTRAQ
名称: 20080308 RE: [Full-disclosure] Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489296/100/0/threaded
来源: BUGTRAQ
名称: 20080308 Re: [Full-disclosure] Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489295/100/0/threaded
来源: BUGTRAQ
名称: 20080307 Re: Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489269/100/0/threaded
来源: BUGTRAQ
名称: 20080306 RE: Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489257/100/0/threaded
来源: BUGTRAQ
名称: 20080306 Re: Firewire Attack on Windows Vista
链接:http://www.securityfocus.com/archive/1/archive/1/489212/100/0/threaded
受影响实体
- Ieee Firewire_ieee:1394<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...