OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
RE: Firewire Attack on Windows Vista

From: Thor (Hammer of God) (thorhammerofgod.com)
Date: Thu Mar 06 2008 - 15:11:43 CST


> -----Original Message-----
> From: Larry Seltzer [mailto:Larrylarryseltzer.com]
> Sent: Thursday, March 06, 2008 9:51 AM
> To: Peter Watkins; Roger A. Grimes
> Cc: Bernhard Mueller; Full Disclosure; Bugtraq
> Subject: RE: Firewire Attack on Windows Vista
>
> >>Roger, you should note that Adam's "Hit by a Bus" paper includes
> information about how Linux users can load their OS' Firewire driver
in
> a way that should disallow physical memory DMA access, and close this
> attack vector.
>
> What are the implications for firewire device compatibility of doing
> this?

Probably the same as just disabling the 1394 bus host controller in
Vista ;)

t