Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Win Explorer wants to connect to sa.windows.com?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Panicware Pop-Up Stopper and JavaScript »
« P2P program causes false attacks?  
AuthorAll Replies


ClmsnTgrFan
Thrifty, Not Cheap
Premium
join:2001-06-02
Crestview, FL
clubs:

reply to andy_c
Re: Win Explorer wants to connect to sa.windows.co

Yeah, this is known behavior. I won't say expected behavior, because I agree it is not expected. Here is an article at the Register about it.

In and of itself, it doesn't seem too bad, but why would it do that by default? Seems like something the user should have to want it to do.

andy_c

join:2001-01-31
Louisville, CO
·ViaTalk


Thanks for that article reference. It covers what I was seeing with Media Player as well.

This all came about when I started thinking about an issue that came up at work. I work for a company that makes a very expensive (5 figures) piece of software. It uses a third-party protection scheme which is known to have been defeated by crackers. Our code actually uses the IWebBrowser COM interface to Internet Explorer to connect to a web site, and upload and log IP address and registration key information in an attempt to identify known cracked license keys. Even people who have personal firewall software will usually still allow Internet Explorer full access, so this process will typically go undetected. I realized that this whole IWebBrowser interface issue represented what I consider to be a significant risk, if not to security, then at least to privacy. So I decided that connecting through Internet Explorer was something I didn't want my system to do at all.

Getting back to these MS programs connecting without my consent, there's another thing that's still bugging me: I wasn't getting these messages when I allowed Proxomitron (and thus IE through HTTP) full access. So this says these programs are trying to connect in two different ways - first through the back door of IE (probably using the IWebBrowser interface), then using code within the program itself. This sure looks to me like "Try the least easily detected technique first, and if that doesn't work, try the more efficient but more easily detected approach of using code that's within the program itself". As a developer myself, I can't think of a good explanation for attempting a less efficient approach first, other than just being sneaky.

Andy C
[text was edited by author 2002-11-25 12:41:06]


ClmsnTgrFan
Thrifty, Not Cheap
Premium
join:2001-06-02
Crestview, FL
clubs:

Glad the article was useful.

Do you have any references for the IWebBrowser thing? I haven't heard of it before, but it sounds like a huge security hole. I did a few quick web searches, but found nothing that really explains it.

Thanks.

andy_c

join:2001-01-31
Louisville, CO
·ViaTalk


Here's the MSDN info: http://msdn.microsoft.com/library/default.asp?url=/workshop/browser/prog_browser_node_entry.asp

The method for sending data to a web server is the IWebBrowser2::Navigate() method described here:
http://msdn.microsoft.com/workshop/browser/webbrowser/reference/IFaces/IWebBrowser2/Navigate.asp
Notice the fourth argument, "PostData". That's the data to send to the server. Here's the description: "PostData [in] Pointer to data to send with the HTTP POST transaction. For example, the POST transaction is used to send data gathered by an HTML form."

Andy C
[text was edited by author 2002-11-25 13:46:57]
Forums » Up and Running » Security » SecurityPanicware Pop-Up Stopper and JavaScript »
« P2P program causes false attacks?  


Saturday, 28-Nov 16:11:17 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [76] TiVo Sees Record Customer Losses
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [62] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Why would I want an e reader? [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· [WIN7] What Win 7 version has Complete Backup and Restore [Microsoft Help]
· Blue Ray: Samsung BD-P3600 or LG BD390 [Audio/Video Chat]
· [Vista] Why is HD So Full? [Microsoft Help]
· Why does it take so long? Mail question [General Questions]
· Gizmo5 has added a Google Voice section in its members area. [VOIP Tech Chat]