Drive-By Exploits Pushing Ransomware Now Able To Bypass Microsoft EMET (arstechnica.com)
An anonymous reader writes from a report via Ars Technica: Ars Technica reports that drive-by attacks that install the TeslaCrypt crypto ransomware are now able to bypass Microsoft's Enhanced Mitigation Experience Toolkit (EMET), which is designed to block entire classes of Windows-based exploits. The EMET-evading attacks are included in Angler, a toolkit for sale online that provides ready-to-use exploits that can be stitched into compromised websites. Researchers from FireEye published a blog post Monday that says the new Angler attacks are significant because they're the first exploits found in the wild that effectively pierce the mitigations. The exploits' code is based on the Adobe Flash and Microsoft Silverlight browser plugins that bypass data execution prevention, a protection that prevents computers from running data loaded into memory. The new Angler exploits rely on techniques other than Data Execution Prevention (DEP) that are harder to detect and contain fewer limitations. FireEye researchers have observed the exploits working only on Windows 7 and not on Windows 10, which is more resistant to exploits. They also only work when targeted computers have either Flash or Silverlight installed. Microsoft created EMET to largely block entire classes of memory-based software exploits that had existed for decades. Now, Angler developers have struck back with techniques that can undo some of those protections. Recently, the TeslaCrypt ransomware makers closed down shop and released a master key and an apology.
Why does Adobe Flash and Microsoft Silverlight browser plugins bypass data execution prevention?
It is pitch black. You are likely to be eaten by a grue.
Make daily back-ups. Never pay a red cent to that filth. It'll go away if we stop paying them. Maybe we should make it illegal to pay them, as well as for them to do what they do.
Hey, don't worry, Windows is as secure as ever!
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.