BufferShield 1.01k
BufferShield is
a security tool for Windows®, capable
of detecting and preventing the exploitation of buffer
overflows, responsible
for the majority of security
related problems faced today.
Upon detection it creates an entry within the event log
and optionally terminates the application in question,
preventing the execution of potentially malicious code.
Buffer overflows are commonly used by hackers
and
viruses to
introduce malicious code into your systems.
For example the Zotob, Sasser or LovSan / MSBlaster
worms
used
such a technique to attack remote
systems.
Click
here
for a more detailed explanation on
how a
buffer overflow can be exploited.
BufferShield uses similar technologies, implemented
by the PaX
project to protect the Linux platform from
buffer overflows.
The commercial version of BufferShield is the only
product available for Microsoft platforms allowing the
definition of a protection scope, specifying which
applications or services should or should not be
protected. Additionally the protection scope allows
the exclusion of certain memory ranges that should
be excluded. This is necessary because some
applications actually generate dynamic code on the
stack or heap and attempt to execute it afterwards,
being detected by BufferShield as an attempted
exploitation of a buffer overflow.
BufferShield's key features:
-
Detects code execution on the stack, default
heap, dynamic heap, virtual memory and data
segments
-
Can terminate applications in question if a
buffer overflow was detected
-
Reports to the
Windows® event log in
case of any detected overflows
-
Allows the definition of a protection scope to
either protect only defined applications or to
exclude certain applications or memory ranges
from being protected
-
Utilizes Intel NX / AMD no-execute hardware
based technology if available
-
SMP support
-
Address Space Layout Randomization (ASLR)
Opposed to the
commercial version of BufferShield,
protecting all running applications and services,
the freely available version is only protecting the
following applications:
BufferShield supports the following operating
systems:
Microsoft Windows® NT 4.0 Server
Microsoft Windows® NT 4.0 Server Enterprise
Edition
Microsoft Windows® NT 4.0 Terminal Server
Edition
Microsoft
Windows® 2000
Professional
Microsoft
Windows® 2000
Server
Microsoft
Windows® 2000 Advanced Server
Microsoft
Windows® XP
Professional
Microsoft
Windows® XP Home Edition
Microsoft
Windows® 2003
Server Standard Edition
Microsoft Windows® 2003 Small Business
Server
Microsoft Windows® 2003 Server Enterprise
Edition
Microsoft Windows® 2003 Server Web Edition
Microsoft Windows® 2003 Datacenter Edition
Existing
client base:
Downloads:
Customers and 30-day trial participants can rely
on our experienced product support, available
24 / 7
using our live
support chat or by contacting us by email.
The live support chat
requires that ActiveScript
(Internet Explorer) or JavaScript (others)
is enabled.
Resellers and VARs wanted, please
contact us.
|