1 Jan 2007 09:47
Re: [OOT] Thesis for master degree
andur matrix <andurmatrix <at> gmail.com>
2007-01-01 08:47:22 GMT
2007-01-01 08:47:22 GMT
Hi,
First make sure which topic you are interested: attacking or defending. They are of quite different philosophy. If you are into attacking in nature, you can not do very well in defending. You will find it boring.
andur.
On 12/18/06, Valdis.Kletnieks <at> vt.edu <Valdis.Kletnieks <at> vt.edu> wrote:
On Sat, 16 Dec 2006 17:55:50 GMT, Aaron Gray said:
>
> >- Disassembling Vista Security
>
> This is illegal. So not a very good idea for the thesis.
This of course is *very* dependent on what country you are in.
In the US, the most important law involved would probably be the DMCA,
which *does* have an exception for reverse engineering for compatibility
research (17 USC 1201(f)), encryption research (17 USC 1201(g)), and
security testing (17 USC 1201(j)).
http://www.law.cornell.edu/uscode/html/uscode17/usc_sec_17_00001201----000-.html
Note that 17 USC 1201(j)(2) *specifically* hints that you *really* want
an in-writing "Get Out Of Jail Free" card for 18 USC 1030 and related.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Sorry for not having ideas just raising more
questions, hope somebody replies in a few pointing out the obvious.
-----Original Message-----
From: full-disclosure-bounces <at> lists.grok.org.uk
[mailto:full-disclosure-bounces <at> lists.grok.org.uk] On Behalf Of Geo.
Sent: Monday, January 01, 2007 8:27 PM
To: full-disclosure <at> lists.grok.org.uk
Subject: [Full-disclosure] Vista Reduced Function mode triggered
The other day I used my router to limit my Vista laptop from talking to
anything but one subnet on the internet. 3 days later suddenly some
things
would not work.
Solitaire failed to start, click on it and you get the magic donut
showing
it's starting up then nothing.
Right click on network and pick properties you get the magic donut
showing
it's starting up then nothing.
So I removed the routes so Vista could once again phone home and within
a
minute or two both solitaire and network properties worked just fine.
Now this Vista system is less than 30 days old and has already been
activated. So the claims that Reduced Function mode only kicks in if you
don't activate within 30 days is bunk if this is Reduced Function mode.
So I decided to trigger RF mode on purpose to see how it responds. I
stopped
the Software License service which claims that doing so will trigger RF
mode. 24 hours later solitaire, network properties, and control panel
all
show the same behavior, the magic donut showing they are starting up
then
nothing. No events in event log, nothing.
I then started the Software License service and presto like magic these
functions work again. So I'm convinced that the machine being routed so
it
can't talk to MS triggered RF mode within a few days. Now to me this
seems
pretty clear even though it wasn't a real scientific method of testing.
And
further, this looks to me like an accident waiting to happen. I mean
imagine
if MS fell off the planet we would have a pretty major problem as the
bulk
of the worlds computers started shutting down, talk about a security
issue?
So anyone here with a bit more technical expertise want to pick up this
ball
and run with it?
Geo.
_______________________________________________
Full-Disclosure - We believe in it.
Charter:
RSS Feed