OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Free Buffer Overflow Protection Software for Windows 2000/XP/2003 Systems

From: A.Denter (A.DenterSYS-MANAGE.NET)
Date: Mon Jan 05 2004 - 07:57:57 CST


BufferShield is security software, capable of detecting and preventing
attempts to execute code on the stack and the heap memory area, in order to
stop the exploitation of buffer overflows. The product is a very useful
addition to Windows Update, minimizing the risk of unresolved security
issues, caused by buffer overflows.

Upon detection of a buffer overflow BufferShield creates an entry within the
event log and optionally terminates the application in question, preventing
the execution of potentially malicious code.

Buffer overflows are commonly used by hackers or viruses to introduce
malicious code into attacked systems.

Opposed to the commercial version of BufferShield, protecting all running
applications and services, the freely available version is limited to
protect only the following list of applications:
-MS Internet Explorer
-Opera
-MS Outlook Express
-MS Outlook

Technically BufferShield enhances the operating system's memory manager to
provide software based support for non executable pages, used to protect the
heap and stack memory area. Microsoft will offer a similar, but hardware
based protection, supporting 64-Bit processors like the AMD K8 or the Intel
Itanium, starting with Windows-XP Service Pack 2 which is currently
available as a beta version.

More information on the upcoming changes and their security and
compatibility implications can be found here:
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnwxp/html/
securityinxpsp2.asp

BufferShield is an affordable alternative for developers, testing their
applications for Windows-XP SP2 readiness, without requiring a 64-Bit
computer system.

A single computer license of the commercial BufferShield version costs
$29.00 and can be ordered on-line from our company's secure website.
Multiple computer and enterprise licenses are also available.

You can download the free version and a 30-day trial of the commercial
version at: http://www.sys-manage.com/index10.htm

By the way, we do not plan to withdraw our free edition, after posting to
this list server, as one of our competitors has already done it. ;)

Kind regards,
Andreas Denter
###########################
Sys-Manage e.K.
Zehnmorgenstr. 48-50
60433 Frankfurt * Germany *
TEL +49-69-979810-82
FAX +49-69-979810-83
WEB http://www.sys-manage.com
mailto:A.DenterSys-Manage.Net

-----
Editor's Note: The 43rd Most Powerful Person in Networking says...

Wondering how to unsubscribe from NTBugtraq? Just send a message to Listservlistserv.ntbugtraq.com with unsubscribe ntbugtraq in the message body, you don't need a subject line. If it says you aren't subscribed, you've either subscribed with a different email address or your address has changed somehow. Just email Russ.Cooperrc.on.ca and I'll remove you.
-----