Internet / Network Security

  1. Home
  2. Computing & Technology
  3. Internet / Network Security

Network Security Blog

From Tony Bradley, CISSP-ISSAP, for About.com

The Threat From Reverse-Engineering Patches

Thursday July 7, 2005
Some people think that malware writers and malicious computer attackers sit around sifting through computer code looking for new and creative ways to exploit and compromise their systems. Security researchers work diligently to discover flaws and security holes and report them to vendors, often in part for the glory and name recognition of finding it first. But, often the attackers don't have that much initiative. It is much easier to wait for a patch to be released and just look at the code in the patch. Rather than tearing the whole program apart, they can reverse engineer the patch to determine what it does, thereby identifying where the flaw exists in unpatched systems. That starts the clock ticking in the race between applying the patch and having an exploit created to compromise vulnerable systems. I first wrote about reverse-engineering Microsoft patches in an article from February of 2004, but with new tools the time between patch release and functional exploit is decreasing rapidly. According to an article in SecurityFocus, using a tool such as BinDiff from SABRE Security, the differences between the original and patched code can be identified in meer minutes and an effective exploit created in under a day. For more about reverse-engineering patches, see Robert Lemos' article "Reverse engineering patches making disclosure a moot choice?

Comments

No comments yet. Leave a Comment

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Explore Internet / Network Security

About.com Special Features

Build Your Own Website

Step-by-step advice on how to do everything from choosing a Web host to promoting your content. More >

Connect Your Home Computers

Easy ways to connect two computers for networking purposes. More >

Internet / Network Security

  1. Home
  2. Computing & Technology
  3. Internet / Network Security

©2009 About.com, a part of The New York Times Company.

All rights reserved.