Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Blocking AutoRun - Re-visited
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Memory Leak in CCSVCHST.EXE (Norton Internet Security 2008) »
« Is it safe to DMZ'd a PS2/3?  
AuthorAll Replies

OZO
Premium
join:2003-01-17

reply to mysec
Re: Blocking AutoRun - Re-visited

Let's make it simple - there should be no way to automatically execute an application from any attached media without explicit user's consent (AutoRun functionality) and there should be no any exception. Period.

If you allow such execution - you facilitate compromising computers. Isn't that simple?

Now, with current implementation of this functionality in WXP SP2 there is no way to execute AutoRun automatically in case if you block it with NoDriveAutoRun or NoDriveTypeAutoRun registry values. But there are cases of deceptive executions that may be done by users. For example:
1) Go to Start|My Computer and click on drive with attached media. Instead of opening its content in explorer (as one may expect) - you execute a startup application immediately.
2) If autorun.inf file contains 'shell\..' instructions replacing Open and/or Explore menu item(s) in context menu for new drive - you may execute a startup application from context menu instead of opening or exploring content of the drive.
No any prompt or warning will be displayed to the user in such cases. It's dangerously wrong and must be fixed ASAP.

Solution should be simple - every time AutoRun instruction is about to be executed (in two cases described above) there should be a dialog box asking for explicit permission to do so. It's imperative that it should be done without any exception. Dialog box should display explicit name of a program that is asking for permission to run.

Please note: in this post I'm talking about particular AutoRun functionality, and not about AutoPlay functionality, which is different one.
--
Keep it simple, it'll become complex by itself...


Vistaluvr

@rr.com


autoplay...
said by OZO See Profile :

Let's make it simple - there should be no way to automatically execute an application from any attached media without explicit user's consent (AutoRun functionality) and there should be no any exception. Period.

If you allow such execution - you facilitate compromising computers. Isn't that simple?

Now, with current implementation of this functionality in WXP SP2 there is no way to execute AutoRun automatically in case if you block it with NoDriveAutoRun or NoDriveTypeAutoRun registry values. But there are cases of deceptive executions that may be done by users. For example:
1) Go to Start|My Computer and click on drive with attached media. Instead of opening its content in explorer (as one may expect) - you execute a startup application immediately.
2) If autorun.inf file contains 'shell\..' instructions replacing Open and/or Explore menu item(s) in context menu for new drive - you may execute a startup application from context menu instead of opening or exploring content of the drive.
No any prompt or warning will be displayed to the user in such cases. It's dangerously wrong and must be fixed ASAP.

Solution should be simple - every time AutoRun instruction is about to be executed (in two cases described above) there should be a dialog box asking for explicit permission to do so. It's imperative that it should be done without any exception. Dialog box should display explicit name of a program that is asking for permission to run.

Please note: in this post I'm talking about particular AutoRun functionality, and not about AutoPlay functionality, which is different one.
Solution is Vista... AND which is why UAC prompts is there

OZO
Premium
join:2003-01-17
Actually, it's AutoPlay, not UAC prompt


Vistaluvr

@rr.com

Actually, I am talking about this: No any prompt or warning will be displayed to the user in such cases. It's dangerously wrong and must be fixed ASAP.

If a software wants access to system directories/files, you'll get a UAC prompt is what I am saying

OZO
Premium
join:2003-01-17

As you may have already noticed life is full of tradeoffs. Your solution may work for Vista, but the price of this is - you are prompted so many times and so often (running applications and tools located on your computer), so eventually you'll get relaxed with confirming to UAC requests. It becomes quite annoying to enter your very simple (otherwise you'll get tired even more quickly) password. Those two factors make it less secure.

In this thread we're discussing only specific issue with automatic execution of startup application coming with unknown media. It should not be allowed in the first place. But currently it's done the way that allows un-noticed compromise of Windows computers. And that requires an immediate fix.


Vistaluvr

@rr.com
reply to OZO
Re: Blocking AutoRun - Re-visited

Bleh, it's no wonder people are getting wrong ideas.
Forums » Up and Running » Security » SecurityMemory Leak in CCSVCHST.EXE (Norton Internet Security 2008) »
« Is it safe to DMZ'd a PS2/3?  


Wednesday, 02-Dec 19:05:08 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [161] Comcast Releasing Promised Usage Meter
· [93] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [79] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [38] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
Most people now reading
· MS admits Windows Updates principally created to annoy [Security]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· UBB round 2 at the CRTC [Canadian Broadband]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Ooma changing features [VOIP Tech Chat]
· Bandwidth Limits/Congestion Management - All discussion here [Comcast HSI]
· [WIN7] When exactly should you flash bios when installing new OS [Microsoft Help]
· A little freaky, not sure if its legit. [Spam, Scam and Phishbusters]