
Originally Posted by
john3347
I didn't peruse the article in detail and I may not fully understand the procedure described. I read it to say that this hack bypasses any passwords that are in place making the intrusion not affected by passwords no matter how strong.. Did I misread this point? If my understanding of the procedure is close to correct, a coworker could easily steal research material, etc from another. The bonuses and promotions that could result from such activity is certainly enough motivation for many, many employees. Will it become necessary to encrypt sensitive material to a flash drive and take it home with you? Bitlocker does come with Enterprise and Ultimate editions of W-7. Maybe this is a Microsoft ploy to move businesses all the way to the top (in cost) editions of the OS. I remember several years ago I "sneaked" into the company computer and got the salaries/wages of everyone that worked there. (Several people got a handsome raise as a result.) Might this vulnerability allow something like this happen again in spite of the many times better security employed by businesses today? This hole seems to be a severe security issue to me. and not to be taken lightly in many environments.
Also, as Kevin points out, would it not allow an individual client user to have full control of their machine in violation of network and company policy?
"The software can also able remove a user's password, giving an attacker access to all of their files. Afterwards, VBootkit 2.0 restores the original password, ensuring that the attack will go undetected. "
The IDG News Service is a Network World affiliate.
Yes, I thought I remembered reading something like this. This sounds to me like a VERY serious threat to the business community.
I think the author of the subject article couldn't decide whether they wanted to say "can also remove" or "is also able to remove", or "can also be able to remove" and kinda jumbled things up on this first sentence here.
Your right they can overide the password ! Few traces left of the attack so hard to detect .
Any computer becomes an open book if running windows 7 ! Think MS will need to do something fast or business take up might be very limited !
Last edited by whoosh; 04-29-2009 at 12:59 AM.
Operating System MS Windows 7 Ultimate 64-bit
Computer Type PC
OS Service Pack SP1
CPU Type and Speed Intel Pentium G620 @ 2.60GHz
Motherboard Chipset Foxconn 2ABF (CPU 1)
System Memory Type 8.00 GB Dual-Channel DDR3
System Memory Speed @ 532MHz
Video Card Type and Speed 1024MB GeForce GTS 450 (EVGA)
Video Card Cooling Fan
Video Card Temperature 45 °C
Power Supply Unit (PSU) 700 W
Computer Monitor Hannspree Xm
Sound Card ASUS Xonar D2X Audio Device
Speakers 5.1
Headset/Microphone Logitech
Hard Drive 977GB Seagate ST31000524AS ATA Device (SATA) 24 °C
Optical Drives hp DVD A DH16ABSH ATA Device
Keyboard and Mouse Keboard Logitech | R.A.T games mouse
Modem-Router Type Virgin Media Braodband Hub
Network Speed 100mbit
Anti-virus Software ESET Security Suit
Computer Skill Level Self-Taught Expert
Windows Experience Index 5.9
Favorite Game UT Game of the Year
Favorite Application Magix Video and Music makers .