IEEE1394规格 权限绕过泄露漏洞

漏洞信息详情

IEEE1394规格 权限绕过泄露漏洞

漏洞简介

IEEE1394规格中存在设计错误,可物理访问设备的攻击者使用修改后的FireWire/IEEE 1394客户端,然后绕过通常需要较高物理访问exploit权限的专门限制,便可读写敏感存储区。

漏洞公告

参考网址

来源: XF

名称: firewire-ieee1394-interface-installed(18041)

链接:http://xforce.iss.net/xforce/xfdb/18041

来源: MISC

链接:http://www.theage.com.au/news/security/hack-into-a-windows-pc-no-password-needed/2008/03/04/1204402423638.html

来源: BUGTRAQ

名称: 20080310 Re: [Full-disclosure] Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489342/100/0/threaded

来源: BUGTRAQ

名称: 20080309 Re: Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489335/100/0/threaded

来源: BUGTRAQ

名称: 20080310 RE: [Full-disclosure] Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489330/100/0/threaded

来源: BUGTRAQ

名称: 20080309 Re: [Full-disclosure] Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489322/100/0/threaded

来源: BUGTRAQ

名称: 20080305 RE: Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489189/100/0/threaded

来源: BUGTRAQ

名称: 20080305 Re: Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489175/100/0/threaded

来源: BUGTRAQ

名称: 20080305 Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489163/100/0/threaded

来源: MISC

链接:http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.pdf

来源: MISC

名称: http://storm.net.nz/static/files/ab_firewire_rux2k6-final.pdf

链接:http://storm.net.nz/static/files/ab_firewire_rux2k6-final.pdf

来源: MISC

链接:http://storm.net.nz/projects/16

来源: MISC

链接:http://pacsec.jp/advisories.html

来源: MISC

链接:http://md.hudora.de/presentations/firewire/2005-firewire-cansecwest.pdf

来源: BUGTRAQ

名称: 20041026 pacsec.jp advisory: Firewire/IEEE 1394 Considered Harmful to Physical Security

链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109881362530790&w=2

来源: MISC

链接:http://it.slashdot.org/article.pl?sid=08/03/04/1258210

来源: BUGTRAQ

名称: 20080308 RE: [Full-disclosure] Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489296/100/0/threaded

来源: BUGTRAQ

名称: 20080308 Re: [Full-disclosure] Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489295/100/0/threaded

来源: BUGTRAQ

名称: 20080307 Re: Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489269/100/0/threaded

来源: BUGTRAQ

名称: 20080306 RE: Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489257/100/0/threaded

来源: BUGTRAQ

名称: 20080306 Re: Firewire Attack on Windows Vista

链接:http://www.securityfocus.com/archive/1/archive/1/489212/100/0/threaded

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享