back to article Hackers use Microsoft security tool to pwn Microsoft security tool

FireEye security wonks Abdulellah Alsaheel and Raghav Pande have twisted the barrels of Microsoft's lauded EMET Windows defense gun 180 degrees and fired. Or in other words, they've found a way to disable Redmond's Enhanced Mitigation Experience Toolkit using the Enhanced Mitigation Experience Toolkit. EMET injects anti- …

  1. arctic_haze
    Holmes

    No worrries

    As long as all my data are safely with Microsoft and NSA, why should hacking be a problem?

  2. Anonymous Coward
    Anonymous Coward

    Just checked my version on personal PC and it appears it doesn't self update...

    Why?

  3. Anonymous Coward
    Anonymous Coward

    In before the linux fanboys wake up!

    Cos you know they love a coffee and a dig at MS in the morning!

    1. Anonymous Coward
      Anonymous Coward

      @AC - Re: In before the linux fanboys wake up!

      I don't quite get it. What has MS EMET tool has to do with my Linux desktop and what are we Linux users supposed to win at this ?

      1. Anonymous Coward
        Anonymous Coward

        Re: @AC - In before the linux fanboys wake up!

        *Fwoooosh!*

  4. Pascal Monett Silver badge
    Headmaster

    Used to be their/they're, now it's affect/effect

    I understand the confusion from commentards, not from writers, and especially not from writers with editors supposed to check them.

    Please do not encourage the confused ones in their confusion.

    1. Anonymous Blowhard

      Re: Used to be their/they're, now it's affect/effect

      But be honest; it's nothing like "lose" and "loose" is it?

      1. Anonymous Coward
        Anonymous Coward

        Re: Used to be their/they're, now it's affect/effect

        "But be honest; it's nothing like "lose" and "loose" is it?"

        They are all near-homonyms - apparently with common etymology. Unlike confusing "aloud" and "allowed" - which is also a common mistake. One BBC radio programme's title "Thinking Allowed" could be considered a deliberate play on that.

        That's a problem with English. If you don't get enough reading practice coupled with understanding the meaning - then you rely on the brain's spell checker producing a word that appears phonetically close.

        Whilst checking the etymology of effect/affect I came across two others that cause confusion "afferent" or "efferent". Be thankful IT networks didn't adopt this pair to differentiate "downstream" and "upstream" (whichever is which?)

        http://english.stackexchange.com/questions/125455/are-effect-and-affect-related-to-efferent-and-afferent

        1. Anonymous Coward
          Anonymous Coward

          Re: Used to be their/they're, now it's affect/effect

          "They are all near-homonyms"

          Small hairy ape creatures? What've they got to do with spelling?

      2. Borg.King
        Facepalm

        Re: Used to be their/they're, now it's affect/effect

        Used to live in Loose, just south of Maidstone, in Kent. Nice village.

        I believe they have a Women's Institute.

    2. Captain Badmouth
      Headmaster

      Re: Used to be their/they're, now it's affect/effect

      Their/they're/there shewerly?

      1. allthecoolshortnamesweretaken

        Re: Used to be their/they're, now it's affect/effect

        Whether I care or not depends enirely on the weather.

        1. MrDamage Silver badge

          Whether/Weather

          Whether the wether* cares about the weather?

          *castrated ram for those who have a non-agricultural background.

  5. kryptylomese

    Microsoft will stop at nothing to make you upgrade to Windows 10

    1. Anonymous Coward
      Anonymous Coward

      KB3035583 lives - again!

      Don't understand the down votes on that posting. Last night I received notification of the latest W7 updates on my two PCs. Six optional and only one "important" - which was the hoary chestnut KB3035583 to enable the W10 upgrade. That has been hidden many times on my PCs for about the last 9 months - and MS keep reviving it every few weeks.

  6. Anonymous Coward
    Windows

    I'm alright, Jack!

    Running wall-to-wall Windows 10 here, like 100s of millions of other peeps, so can rest easy.

    1. Anonymous Coward
      Anonymous Coward

      Re: I'm alright, Jack!

      Good for you! Now can you use your influence to politely suggest Microsoft to f.. sorry! to leave the rest of us alone with whatever version of Windows/Linux/Mac we may fancy ? Surely hundreds of millions should be more than enough for Microsoft to ignore the few of us who say thank you very much for your free offer, Microsoft, but no thanks.

  7. Anonymous Coward
    Anonymous Coward

    And the winner is.....

    ...People who upgrade their OS to the latest version?

  8. Roland6 Silver badge

    Problem due to how EMET installs?

    What isn't clear is whether this exploit is possible because EMET is running in user space rather than kernel space.

  9. Zippy's Sausage Factory
    WTF?

    So... the function that unloads EMET can be used to unload EMET? That's a discovery along the lines of when you shoot yourself in the foot, it hurts.

    Isn't this simply using something to do what it's supposed to do to do something you don't want it to do. I can sell you a chainsaw, but if someone breaks into your house and saws off your leg with it, that's really not a problem with the chainsaw, per se, but one of access to the chainsaw.

    Which sounds like it's already fixed, so really no particular annoyance. Although to be fair, I doubt it's ever going to get fixed on anything before Windows 10. I'm going to stop now because I'm really trying hard not to say "all your data are belong to us" here. Oh. Damn.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like