Skip Links

Network World

Julie Bort

Hackers will break virtualization at Microsoft’s BlueHat conference

By Microsoft Subnet on Fri, 09/21/07 - 3:30pm.

Check out this rad cool thingNext week, BlueHat v6 commences. For all the grief the Microsoft security folks get (including landing on a list of worst jobs ), one of the cooler things they do is BlueHat. This is an annual invitational conference in which hackers are invited to Redmond to meet with the Microsoft security Big Cheeses and demonstrate how they break Microsoft products.The theme for v6 is cutely named "The Vuln Behind The Curtain." The targets of this year's hacking will be virtualization and process isolation.

While the conference itself is a closed-door event, Microsoft is fairly open about what is being covered. According to a blog posting from Andrew Cushman , Microsoft's director of security outreach:

"We've got a couple of talks on Windows Mobile and more about automated exploit creation - this time using Metasploit. There will also be a talk on a DNS pinning design issue that demonstrates how Internet Explorer can turn into a VPN concentrator. All this--and talks on Office, Binary Instrumentation, Visualization and the Economics of Security"

ZDNet security blogger, Ryan Naraine, has an interesting take on BlueHat v6, too.

"Researchers are divided over whether hypervisor rootkits presents a realistic threat. Joanna Rutkowska, for example, claims that malware can be made "100% undetectable" but, at this year's Black Hat Briefings, a group of her peers openly challenged that assertion, insisting that virtual machine rootkits are rather easy to detect."

Naraine notes that Microsoft's stake in the debate stems from earlier this year when the company revoked plans that would have had it easing Vista licensing agreements to account for virtualization.

The excuse it used was that hardware virtualization technology was a security risk.

About The Microsoft Update

Julie BortJulie Bort is the editor of Microsoft Subnet and Network World's Online Community Editor. She also writes the Open Source Subnet blog and is the editor responsible for the Cisco Subnet and Open Source Subnet web sites. If you have an idea for a blog, or a news tip on Microsoft, Cisco or Open Source technologies, contact her at jbort@nww.com, 970-482-6454 or follow Julie on Twitter @Julie188.

The Microsoft Subnet blog is the official blog of the Network World's Microsoft Subnet community. Microsoft Subnet is the independent voice of Microsoft customers and is your gateway to daily Microsoft news, blogs, opinion, books, prize giveaways and more. Visit the Microsoft Subnet index page daily, and while you are there, subscribe to the Microsoft newsletter.

Become a Facebook Fan of Julie Bort

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited

 

Most Discussed Posts

Blog Roll
Microsoft Subnet Home Page
http://www.networkworld.com/subnets/microsoft/
All Microsoft Subnet bloggers
http://www.networkworld.com/community/blogs/microsoft/feed
ActiveWin
http://www.activewin.com
Blake Handler The Road to Know Where
http://bhandler.spaces.live.com/
Dmitry's PowerBlog
http://dmitrysotnikov.wordpress.com/
Doug Brown,DABCC
http://www.dabcc.com
Ed Bott's Windows Expertise
http://www.edbott.com/weblog/
Joseph Tartakoff Microsoft Blog
http://blog.seattlepi.nwsource.com/microsoft/
Long Zheng istartedsomething
http://www.istartedsomething.com/
Mini-Microsoft
http://minimsft.blogspot.com/
Paul Thurrott's Supersite for Windows
http://www.winsupersite.com
Robert McLaws WindowsNow
http://www.windows-now.com
Scobleizer
http://scobleizer.com/
Techmeme
http://www.techmeme.com/
Todd Bishop's Microsoft Blog
http://www.techflash.com/Microsoft