ASLR + DEP Bypass Puts Hackers Ahead

When Microsoft shipped Windows Vista,  the addition of security technologies like ASLR (Address Space Layout Randomization) alongside DEP (Data Execution Prevention) and SafeSEH were held up as major roadblocks to hacker attacks.   With every new service pack of OS upgrade, these mitigations got stronger and stronger but, at Pwn2Own, attackers found ways to bypass and defeat these mechanisms.   In typical cat-and-mouse fashion, this shows that the skilled, dedicated hackers with the right motivation will always find ways to stay ahead of the security technologies.

When Microsoft shipped Windows Vista,  the addition of security technologies like ASLR (Address Space Layout Randomization) alongside DEP (Data Execution Prevention) and SafeSEH were held up as major roadblocks to hacker attacks.   With every new service pack of OS upgrade, these mitigations got stronger and stronger but, at Pwn2Own, attackers found ways to bypass and defeat these mechanisms.   In typical cat-and-mouse fashion, this shows that the skilled, dedicated hackers with the right motivation will always find ways to stay ahead of the security technologies.

Suggested articles

2020 Cybersecurity Trends to Watch

Mobile becomes a prime phishing attack vector, hackers will increasingly employ machine learning in attacks and cloud will increasingly be seen as fertile ground for compromise.

Top Mobile Security Stories of 2019

Cybercrime increasingly went mobile in 2019, with everything from Apple iPhone jailbreaks and rogue Android apps to 5G and mobile-first phishing dominating the news coverage. Here are Threatpost’s Top 10 mobile security stories of 2019.