Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Industry News > Software News

Reply
 
LinkBack Thread Tools
Old 02-03-09   #1 (permalink)
You break it, I fix it.
 
noobdown's Avatar
 
amd ati

Join Date: Sep 2006
Location: Overclock.net
Posts: 7,989

Rep: 777 noobdown is becoming famousnoobdown is becoming famousnoobdown is becoming famousnoobdown is becoming famousnoobdown is becoming famousnoobdown is becoming famousnoobdown is becoming famous
Unique Rep: 524
Trader Rating: 3
Default [dailyteck]Windows 7 UAC Leaves Door Open for Attacks

Quote:
Microsoft insists big Windows 7 security hole will not be fixed, is "by design"


When Windows Vista was launched, it brought to the table a new feature that was supposed to safeguard the user: the User Account Control (UAC). However, the useful feature, which could be disabled, became the source of a great deal of the OS's early criticism due its warning messages which some users found irritating.

With Windows 7, Microsoft decided to switch gears and is offering a less nosey UAC in the beta version of the OS. This move was the subject to much early praise. However, it may have now backfired as a blogger Long Zheng, who runs the blog Start Something, has detailed a proof-of-concept attack against the new Windows 7 UAC.

Mr. Zheng says the attack is a vindication of Windows Vista, and evidence that the new Windows 7 approach, while more pleasing to some, is inherently insecure. He states, "This is dedicated to every ignorant ‘tech journalist’ who cried wolf about UAC in Windows Vista. A change to User Account Control (UAC) in Windows 7 (beta) to make it ‘less annoying’ inadvertently clears the path for a simple but ingenious override that renders UAC disabled without user interaction. For the security conscious, a workaround is also provided at the end. First and foremost, I want to clear up two things."

The flaw, which he calls "blatantly simple" to fix, was raised to his attention by a "security-minded 'whistleblower.'" Ignored largely by Microsoft in chatter in its Windows 7 beta feedback, the issue may be present in the retail version of Windows 7 and has been known to many for some time.

Normally Windows 7 is set with the options "Notify me only when programs try to make changes to my computer" and "Don’t notify me when I make changes to Windows settings". It uses a security certificate to determine if a program is part of Windows -- in other words, changes in the control panel don't raise warnings as they have a trusted certificate.

The "Achilles heel" as Mr. Zheng describes is that the UAC is a certified program and thus changes to it are also trusted -- even if that change is to disable it. While he admits that he had to "think bad thoughts" to come up with a way of disabling the UAC without directly tricking the user into doing it, he says it wasn't tough. He has posted a proof-of-concept VBScript, which uses keyboard shortcuts to select the UAC and then disable it. The attack works against any user who has administrative permissions (as standard users are prompted for an administrative password when changing the UAC settings).

He elaborates, "We soon realized the implications are even worse than originally thought. You could automate a restart after UAC has been changed, add a program to the user’s startup folder and because UAC is now off, run with full administrative privileges ready to wreak havoc."

He adds, "This is the part where one would usually demand a large sum of money but since I’m feeling generous, there is a simple fix to this problem Microsoft can implement without sacrificing any of the benefits the new UAC model provides."

The fix, he says is to force the UAC into a secure desktop mode, whenever the UAC is changed, regardless of its state. This, he says, while by no means foolproof, will prevent basic attempts. He suggests Microsoft adopt the fix as soon as possible.

Microsoft, however, appears to be relaxed about the topic, as it responded to Mr. Zheng that the flaw is "by design", indicating it will not be changed before release. Furthermore, as of this morning it has pulled a MSDN post about the topic which Mr. Zheng linked.
http://www.dailytech.com/Windows+7+U...ticle14127.htm
__________________
ATi 4830 Club


Official Cooler Master 690 Club
Quote:
Originally Posted by Syrillian View Post
Have a rest... sometimes it is the Human that needs the re-set.


System: my sig was stolen.
CPU
p2
Motherboard
dell
Memory
215m 133
Graphics Card
ati rage
Hard Drive
10g
Power Supply
250w dell
noobdown is offline Overclocked Account   Reply With Quote
Old 02-03-09   #2 (permalink)
Renholdër
 
Penicilyn's Avatar
 
intel ati

Join Date: Jan 2006
Location: Kitchener, ON, Canada
Posts: 8,669

Rep: 846 Penicilyn is becoming famousPenicilyn is becoming famousPenicilyn is becoming famousPenicilyn is becoming famousPenicilyn is becoming famousPenicilyn is becoming famousPenicilyn is becoming famous
Unique Rep: 646
Trader Rating: 1
Default

Cool I think it's a good thing, now how can I remove UAC all together?
__________________
GRID Drift Club
OCN Headphones Club - Because Perfect Hair is Overrated
ATI - We Are the Red Tide
Canadian OCN Club
http://www.overclock.net/view.php?pg=rulestos The TOS
Quote:
Originally Posted by NitroDell View Post
and suddenly my porn videos dont seem as "clear" as they once did before on XP with WMP 10

System: The Money Hole
CPU
E8400 SLB9J @ 4.21Ghz 1.264vCore
Motherboard
Asus P5Q-E
Memory
2x2Gb Patriot DDR2-800mhz
Graphics Card
Visiontek 4850 & Sapphire 4850
Hard Drive
2x WD Black 640Gb (RAID0), 1x WD 320Gb
Sound Card
Sound Blaster Audigy 4
Power Supply
Corsair TX750w
Case
Lian Li PC-7 Plus II
CPU cooling
Scythe Ninja 2
GPU cooling
2x A.C S1 rev.2 Passive
OS
Win7 x64 Ultimate / Mint 7 x64
Monitor
LG W2254TQ 22"
Penicilyn is offline Overclocked Account Penicilyn's Gallery   Reply With Quote
Old 02-03-09   #3 (permalink)
Battlecruiser Operational
 
justarealguy's Avatar
 
intel nvidia

Join Date: Jul 2007
Location: South NJ
Posts: 4,226

Rep: 257 justarealguy is a proven memberjustarealguy is a proven memberjustarealguy is a proven member
Unique Rep: 209
Folding Team Rank: 324
Trader Rating: 10
Default

People complain UAC is in their face too much.

Then they complain when it's not around enough.

I really feel bad for MSFT.
__________________
Quote:
Originally Posted by The Duke View Post
Rename something, that will fix things for nVidia.

System: College Dorm Rig
CPU
Q6600 G0 @ 3.0-3.6GHz
Motherboard
EVGA 750i
Memory
2x2gb OCZ / 2x2GB A-Data
Graphics Card
EVGA GTX 260 (216)
Hard Drive
300GB Velociraptor, 640GB Blue, 1.5TB Green
Sound Card
Creative X-Fi XtremeMusic
Power Supply
Corsair HX620
Case
Antec 300 | 4x 50cfm/<30db
CPU cooling
TRUE w/ 50CFM YateLoon
GPU cooling
Stock
OS
Win7 64bit
Monitor
22" Samsung 1680x1050
justarealguy is offline I fold for Overclock.net Overclocked Account   Reply With Quote
Old 02-03-09   #4 (permalink)
WaterCooler
 
killnine's Avatar
 
intel ati

Join Date: Aug 2005
Posts: 3,363

Rep: 161 killnine is acknowledged by manykillnine is acknowledged by many
Unique Rep: 144
FAQs Submitted: 1
Trader Rating: 9
Default

Quote:
Originally Posted by justarealguy View Post
People complain UAC is in their face too much.

Then they complain when it's not around enough.

I really feel bad for MSFT.
QFT.

People first make a big deal about the boxes double-checking what you do.


Now its like "hey, not enough boxes!"

System: Teh System
CPU
Intel i7 920 (3.2Ghz @ 1.0V)
Motherboard
Asus Rampage II Gene
Memory
6Gb Corsair XMS DDR3 (1333)
Graphics Card
VisionTek 4870
Hard Drive
Seagate 7200rpm (160)
Sound Card
X-fi Fatal1ty Pro
Power Supply
Silverstone Strider 750W
Case
Mini P180B
CPU cooling
OCZ Vendetta 2
GPU cooling
HR-03 GT
OS
Windows 7 (x64) RC1
Monitor
Dell 2001FP 20.1&quot;

Last edited by t4ct1c47 : 02-03-09 at 07:38 PM
killnine is offline   Reply With Quote
Old 02-03-09   #5 (permalink)
Gunga Lagunga
 
dralb's Avatar
 
intel ati

Join Date: Jan 2007
Location: Cloud 9
Posts: 6,717

Rep: 659 dralb is becoming famousdralb is becoming famousdralb is becoming famousdralb is becoming famousdralb is becoming famousdralb is becoming famous
Unique Rep: 462
Folding Team Rank: 263
Trader Rating: 17
Default

I am a bit confused. Does this imply that the person disabling UAC already has access to the PC? I guess what I am asking is, can this be disabled remotely? If so, you would need to be vulnerable in the first place, right?

How does this change from having the same security and habits as any OS without UAC? Just because it CAN be disabled doesn't mean people can access it easily, right? (or, not as easily or as hard as any other type or breach)
__________________
Antec 1000 Case Mod Worklog

3358 Windsor 3800

"[Vietnam] only made billionaires out of millionaires. Today's war is making trillionaires out of billionaires. Now I call that progress." -Kurt Vonnegut

System: Bobo
CPU
Q6700 @ 3.9 ghz
Motherboard
GA-EP45-UD3P
Memory
G.Skill 2x2gb, 1027mhz
Graphics Card
Gigabyte 4870 1gb 790/925
Hard Drive
2x WD 500 AAKS RAID0
Power Supply
Corsair 520hx
Case
A900
CPU cooling
D-Tek V1
GPU cooling
Stock
OS
Vista Ultimate
Monitor
Westinghouse 22" WS & Hanns G 17"
dralb is online now I fold for Overclock.net Overclocked Account   Reply With Quote
Old 02-03-09   #6 (permalink)
News Fiend
 
Urufu_Shinjiro's Avatar
 
intel nvidia

Join Date: May 2005
Location: Albany, Ga.
Posts: 3,591

Rep: 170 Urufu_Shinjiro is acknowledged by manyUrufu_Shinjiro is acknowledged by many
Unique Rep: 135
Trader Rating: 2
Default

Quote:
Originally Posted by dralb View Post
I am a bit confused. Does this imply that the person disabling UAC already has access to the PC? I guess what I am asking is, can this be disabled remotely? If so, you would need to be vulnerable in the first place, right?

How does this change from having the same security and habits as any OS without UAC? Just because it CAN be disabled doesn't mean people can access it easily, right? (or, not as easily or as hard as any other type or breach)
It's no different, just some people have to hate on M$ or they're not in the cool crowd, lol. Even in beta win7 is the best thing to come out of Redmond for a long time, if not the best thing ever.
__________________
Piracy is not theft, stop the future before it happens! May Sever protect us all!

Please listen to Tales From the Afternow!

Disclaimer: Listening to the above referenced audio may violate the terms of your listeners license and may result in termination. Remember, unregulated speech is pornography, sharing is theft.

System: My System
CPU
Q6600 GO Vid 1.235
Motherboard
Asus Maximus/Rampage
Memory
2x2gb G.Skill 1066 Pi
Graphics Card
EVGA 8800GTS G92
Hard Drive
2xMaxtor 200gb RAID0
Sound Card
X-Fi xtreme music
Power Supply
Silverstone 600w modular
Case
CM Stacker 810
CPU cooling
Custom Water
GPU cooling
Custom Water
OS
Vista Ultimate X64
Monitor
24" Acer AL2416W S-PVA
1 Million+ Folding at Home points
Urufu_Shinjiro is offline   Reply With Quote
Old 02-03-09   #7 (permalink)
Over 9000.
 
ChielScape's Avatar
 
amd nvidia

Join Date: May 2007
Location: The Netherlands
Posts: 9,123

Rep: 671 ChielScape is becoming famousChielScape is becoming famousChielScape is becoming famousChielScape is becoming famousChielScape is becoming famousChielScape is becoming famous
Unique Rep: 462
Trader Rating: 0
Default

Quote:
Originally Posted by jayrcr3 View Post
i'm gonna cry!
behavior like that makes me cry. try to act a little grown up here, a little respect can get you pretty far in life.
__________________
Quote:
Originally Posted by StrongmanSal View Post
^^^^^ this dude right here ^^^^^^^^ is one true badass.
ChielScape is offline Overclocked Account ChielScape's Gallery   Reply With Quote
Old 02-03-09   #8 (permalink)
4.0 GHz
 
SolShade's Avatar
 
intel nvidia

Join Date: Sep 2007
Location: your pants
Posts: 549

Rep: 14 SolShade Unknown
Unique Rep: 14
Trader Rating: 0
Default

If people are dumb enough to run every script file they come across they deserve to be infected.
Website:"Download this movie player to watch free porn!!!!!"
User: OK
There is nothing MS can do to prevent inherent stupidity.
__________________
It's not gonna overclock itself.
Quote:
Originally Posted by Brutuz View Post
Ew, ASUS, its like some famous girls, looks flashy, but when you use it, you feel violated and think you might of caught something.

System: Unholy Union
CPU
i7920 @ 4ghz 1.42V
Motherboard
Asus P6T6 Revolution
Memory
mushkin ddr3
Graphics Card
eVGA 8800 Ultra
Hard Drive
4 WD Raptors in raid 0
Sound Card
onboard -_-
Power Supply
PC PnC 1kw
Case
2 Lian-Li A16Bs
CPU cooling
Swiftech Apogee GTZ
GPU cooling
DD 8800gtx waterblock
OS
Windows 7 x64
Monitor
Samsung 22inch LCD ws
SolShade is offline   Reply With Quote
Old 02-03-09   #9 (permalink)
WaterCooler
 
MikersSU's Avatar
 
intel nvidia

Join Date: Nov 2007
Location: Ossining/White Plains, NY
Posts: 945

Rep: 68 MikersSU is acknowledged by some
Unique Rep: 62
Folding Team Rank: 1194
Trader Rating: 13
Default

I personally don't mind UAC much. I got used to it. Win7 is in beta testing. I'd rather wait till the finished product to pass judgement. Hopefully MS will address this issue...or by a feat of miraculous proportions, people will develop common sense en masse and stop clicking on pop-ups or cruise free porn/malware sites.

*shrug* There's always hope...
__________________
System: Insanoflex
CPU
Core i7 920 4+Ghz 3844AXXX 1.28v D0
Motherboard
Asus P6T Deluxe OC Useless Palm
Memory
3x2GB G Skill DDR3 1600
Graphics Card
eVGA GTX 285
Hard Drive
1xCaviar SE16 640 and 1xCaviar SE16 750GB
Sound Card
X-Fi Auzentech Forte
Power Supply
PC Power & Cooling Silencer 750
Case
Mountain Mod U2-UFO
CPU cooling
Swiftech Apogee GTZ
GPU cooling
Stock
OS
Vista 64 Ultimate
Monitor
22" 120Hz Samsung
MikersSU is offline I fold for Overclock.net   Reply With Quote
Old 02-03-09   #10 (permalink)
4.1GHz and counting...
 
onlycodered's Avatar
 
intel nvidia

Join Date: Mar 2008
Location: Rochester, NY
Posts: 4,051

Rep: 271 onlycodered is a proven memberonlycodered is a proven memberonlycodered is a proven member
Unique Rep: 223
Trader Rating: 15
Default

Quote:
Originally Posted by justarealguy View Post
People complain UAC is in their face too much.

Then they complain when it's not around enough.

I really feel bad for MSFT.
This is exactly what I just said when I turned around to my co-worker after reading this article. I'm starting to feel somewhat bad for Microsoft. Everything they do gets criticized.
__________________
Quote:
Originally Posted by GH0 View Post
So, as a staff from EVGA has told me to do:
PLEASE DO NOT EVER BUY ANOTHER EVGA PRODUCT AGAIN.
Fold for the cause. Fold for team 37726!
Former "The Replacements" folding team member
CPU-Z valid GPU-Z valid

System: Desktop
CPU
E8400 (4.1GHz / 1.33v)
Motherboard
Gigabyte P35-DS3L rev 2
Memory
2x2GB mushkin XP2-8500 DDR2 1066
Graphics Card
XFX GeForce GTS 250 1GB Core Edition
Hard Drive
WD Caviar Black 640GB
Sound Card
Integrated
Power Supply
Xigmatek NRP-MC751 750W
Case
Antec Three Hundred
CPU cooling
Xigmatek Thor's Hammer / D12SM-124B
OS
Windows 7 Professional x64
Monitor
Samsung 2253BW
onlycodered is offline Overclocked Account onlycodered's Gallery   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 10:00 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.22545 seconds with 8 queries