<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Windows XP &amp; Vista Full Take-over Hack with Firewire</title>
	<atom:link href="http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-125340</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Mon, 05 Jan 2009 22:52:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-125340</guid>
		<description>Clarkson,

The attack mentioned does have some practical application.
Imagine a workstation with full disk encryption. Having physical access to the workstation is not much use. Now, if the workstation is powered, but locked, the attacker can gain access to the OS using this method.</description>
		<content:encoded><![CDATA[<p>Clarkson,</p>
<p>The attack mentioned does have some practical application.<br />
Imagine a workstation with full disk encryption. Having physical access to the workstation is not much use. Now, if the workstation is powered, but locked, the attacker can gain access to the OS using this method.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clarkson</title>
		<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-125339</link>
		<dc:creator>Clarkson</dc:creator>
		<pubDate>Mon, 05 Jan 2009 20:32:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-125339</guid>
		<description>Just pick up the machine and walk out with it, if you have physical access to the box.</description>
		<content:encoded><![CDATA[<p>Just pick up the machine and walk out with it, if you have physical access to the box.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fever</title>
		<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-122708</link>
		<dc:creator>fever</dc:creator>
		<pubDate>Thu, 10 Apr 2008 16:43:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-122708</guid>
		<description>another example of disable that which you do not use. Or it will come to bite you in the end.</description>
		<content:encoded><![CDATA[<p>another example of disable that which you do not use. Or it will come to bite you in the end.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120538</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Fri, 21 Mar 2008 15:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120538</guid>
		<description>Have to agree too - the ways of taking over a machine are plentiful if you have physical access to it.</description>
		<content:encoded><![CDATA[<p>Have to agree too &#8211; the ways of taking over a machine are plentiful if you have physical access to it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James C</title>
		<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120524</link>
		<dc:creator>James C</dc:creator>
		<pubDate>Fri, 21 Mar 2008 14:40:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120524</guid>
		<description>@Darknet
&quot;As I’ve always said though, if you have physical access you basically own the machine.&quot; 
This is especially true if you pick up the computer and run out the building with it.</description>
		<content:encoded><![CDATA[<p>@Darknet<br />
&#8220;As I’ve always said though, if you have physical access you basically own the machine.&#8221;<br />
This is especially true if you pick up the computer and run out the building with it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120504</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Fri, 21 Mar 2008 13:24:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120504</guid>
		<description>A fun thing to read.

Like Bogwitch says, it&#039;s a bus and has direct DMA access, basically needed since most of the firewire attached stuf is a HDD or other drive which want/need DMA access. Did a trial with disabled DMA but trying to capture video from the firewire attached hi-8 cam results in significant more frame loss compared to having DMA turned on. The direct DMA access appears to be needed to ensure a proper dump of the data coming in at the firewire onto the hdd (both p-ATA and s-ATA are fast enough to capture the 4 Mb datastream).

@Darknet, indeed a makeshift secured broom cupboard (padlock/etc and steel plate reinforced door) is enough to keep out the average purp.</description>
		<content:encoded><![CDATA[<p>A fun thing to read.</p>
<p>Like Bogwitch says, it&#8217;s a bus and has direct DMA access, basically needed since most of the firewire attached stuf is a HDD or other drive which want/need DMA access. Did a trial with disabled DMA but trying to capture video from the firewire attached hi-8 cam results in significant more frame loss compared to having DMA turned on. The direct DMA access appears to be needed to ensure a proper dump of the data coming in at the firewire onto the hdd (both p-ATA and s-ATA are fast enough to capture the 4 Mb datastream).</p>
<p>@Darknet, indeed a makeshift secured broom cupboard (padlock/etc and steel plate reinforced door) is enough to keep out the average purp.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120471</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Fri, 21 Mar 2008 11:05:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/03/new-windows-xp-vista-full-take-over-hack-with-firewire/#comment-120471</guid>
		<description>It&#039;s not just MS OSes that are vulnerable to this - anything with an active firewire.
The reason it can access the memory direclty is that Firewire is a BUS whereas USB etc. is a PORT.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not just MS OSes that are vulnerable to this &#8211; anything with an active firewire.<br />
The reason it can access the memory direclty is that Firewire is a BUS whereas USB etc. is a PORT.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
