Secure Coding mailing list archives

Dark Reading - Application and Perimeter Security - Hacking the Vista Kernel - Security News Analysis


From: secureCoding2dave at davearonson.com (SC-L Subscriber Dave Aronson)
Date: Tue, 25 Jul 2006 20:15:46 +0000

Pete Shanahan [mailto:petesh at indigo.ie] writes:

I'm just wondering how flawed the implementation of the windows
paging model is that it would allow for this kind of breach. The
standard model I'm familiar with would simply flush the page from
memory, and would not keep a copy in the external page-file,
instead relying on the copy that already exists on the disk.

Perhaps the code in question is stored compressed, so that there is no verbatim copy already on disk.  (I have no clue 
if Windows does this.)

-Dave




Current thread: