Eye on Security: Vista 7 is 'Secure', They Promised
- Dr. Roy Schestowitz
- 2010-11-30 21:34:07 UTC
- Modified: 2010-11-30 21:34:07 UTC
Summary: Vista 7 -- just like Vista and its processors -- is still Swiss cheese based on the latest news
●
Breaking That Other OS
Yet another means of exploiting that other OS has been demonstrated by Sophos. An ordinary user can gain complete control of the system whether it is XP, Vista, “7ââ¬Â³ etc. simply by running some code that tweaks a key in the registry. A workaround is to create a new key to block users from changing keys in the registry… Duh… How’s that for backwards compatibility?
This is another demonstration that M$ has created a monster running on nearly every PC on the planet that invites compromise. Now, hundreds of millions of users will have to do some dance with updates or tweak the registry themselves to do something that M$ neglected to do many years ago.
●
'Nightmare' kernel bug lets attackers evade Windows UAC security
Microsoft is investigating reports of an unpatched vulnerability in the Windows kernel that could be used by attackers to sidestep an important operating system security measure.
One security firm dubbed the bug a potential "nightmare," but Microsoft downplayed the threat by reminding users that hackers would need a second exploit to launch remote attacks.
●
Newly discovered Windows kernel flaw bypasses UAC
Last week an exploit for a Windows kernel flaw was published by an unknown source. Presumably as a joke, details of the flaw, along with proof-of-concept code, were published on Code Project. Code Project is a programmer peer support community, containing many tutorials and useful snippets of code to assist developers. Malware developers are not the usual target audience for posts made to the site, and so perhaps unsurprisingly, the article has been removed (though is mirrored here).
The flaw is a privilege escalation vulnerability. Anyone who can run code on a Windows system can elevate her privileges to the highest level, and accordingly install back doors, compromise sensitive data, and so on. The flaw lies in a critical Windows driver called win32k.sys. The driver inappropriately handles certain data stored in the registry—data that is stored on a per-user basis, and hence accessible to any unprivileged program. The proof-of-concept code uses this flaw to elevate the privileges of the user running the demo code; it could just as well be used to install a back door or other malware.
Recent Techrights' Posts
- Confirmed in French Media: Mass Layoffs (10% Culled) in Microsoft France
- Now some reports in French
- Microsoft in Freefall in Finland
- Can Finland eradicate Windows from all its infrastructure, including core operations that are sensitive to sabotage by cracking?
- Google's Chrome Passes 70% and Web Standards Are Dying
- The Web is quickly becoming devoid of any standards
- Slopwatch: Plagiarism and Ponzi Scheme, Bubble About to Burst Entirely, Admits Goldman Sachs
- the hype that Google News and The Register MS actively participate and profit from
- The Register MS Says "AI Web Crawlers Are Destroying Websites", So Why Does The Register MS Help 'AI' Companies? (Spoiler: Money)
- People need to call out The Register MS on its hypocrisy
- Slopfarms Already Peaked, They Will Die When Slop Companies Run Out of Money to Borrow
- slopfarms will lack an actual "engine"
- Why We Publish Information About the SLAPPs (But Not About the Legal Process), an Abuse of Process by Americans Trying to Silence Critics of Their Employer, Microsoft
- It doesn't take thousands of pages to explain something simple
-
- Links 02/09/2025: Oligarch Tech and Text Encoding Concerns in Ada
- Links for the day
- "Internal Changes at Red Hat / IBM"
- It seems like quite a few people are leaving
- "People on LinkedIn Saying That They've Left Red Hat."
- We already saw signs of it a month ago and named some of the people
- Gone With the BRICs (or BRICS): "Linux 8" in Cuba
- GAFAM must be worried
- Telecompaper Reports Microsoft to Reduce the Workforce by Another 10% (in France)
- Imagine what this will do to staff's morale
- India is Back to Windows 8 (Market Share Down to 8%) as Android Soars to a New Record High
- For Microsoft, India is a runaway market
- Links 02/09/2025: SCO Summit and Russia Suspected Of Jamming GPS
- Links for the day
- Gemini Links 02/09/2025: Mediterranean Marriage and Staying Connected at 35,000 Feet
- Links for the day
- Links 02/09/2025: Attacks on Unions, Microsoft TCO, and DDoSing a Growing Problem
- Links for the day
- Internet Relay Chat Didn't Fall Off a Cliff
- IRC will turn 40 in less than 3 years from now
- The UEFI 9/11 - Part V - This is Not a Drill (Disable "SecureBoot" Now)
- A "9/11" Coming
- There's No Obligation to Speak to Anybody
- The very fact that "bkuhn" is till spending time in social control media says a lot about his poor judgment
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, September 01, 2025
- IRC logs for Monday, September 01, 2025
- Microsoft Trying to Force People to Resign (Amid Mass Layoffs) a Strategy That Takes Its Toll
- Microsoft seems to be circling down the drain and the "final flush" will be the moment the "hey hi" (AI) bubble implodes completely
- Google Simply Cannot Be Trusted
- Only fools would trust GAFAM
- Admission That a Third Party (or Parties) Funds the SLAPPs Against Techrights
- This can end up costing them over a million dollars
- Modifying and Writing One's Own Computer Programs is Not a Crime (or: Google Proves That Stallman Was Right)
- We're generally gratified to see so many positive mentions of him
- Why We Stopped Publishing Videos (for Now)
- We'll probably get back to videos one day, but it's hard to say when or to what extent
- What Animal Rights Activism Teaches Us About Sympathy and Focus
- It's possible to believe that the planet is warming, that we must do something about it, and still eat eggs and butter
- When You Turn Web Sites About Tech Into Political Sites
- A lot of people fall into the trap of catering only for particular groups
- Gemini Links 02/09/2025: ROOPHLOCH 2025 and Lagrange 1.19 Released
- Links for the day
- Gemini Links 01/09/2025: News Corp. WSJ and A Month With NixOS
- Links for the day
- “Sideloading” Never Killed Anybody
- There are many online discussions this week about the misnomer "sideloading"
- Slopwatch: Google News as FUD Vector Against Linux and Plagiarism Enhancer, Serial Slopper (SS) Uses LLMs to Googlebomb "Linux"
- Slop destroys the Web not just by screwing with search engines and helping plagiarists. It's also responsible for de facto DDoS attacks...
- Links 01/09/2025: "Attacks on Science" and China's "Soft Power" Grows
- Links for the day
- Links 01/09/2025: Fresh Backlash Against Slop and "Norway’s Electricity Crisis is About to Hit Britain"
- Links for the day
- Writing and Coding Isn't Always Enough
- Last year we had to assume a role we didn't have before: litigants
- Links 01/09/2025: Catching Up (Mostly via Deutsche Welle), "Windows TCO" Effect in UK
- Links for the day
- Gemini Links 01/09/2025: Linguistic Barriers and "Web 1.0 Hosting"
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, August 31, 2025
- IRC logs for Sunday, August 31, 2025
- Autumn Has Come
- Autumn should be exciting in all sorts of ways; it'll also mark our anniversary
- The UEFI 9/11 - Part IV - External Interference
- They all seem to be playing a role in crushing Software Freedom and self-determination for users
- Links 31/08/2025: Baggage Claim Scams, an Insurrectionist’s War on Culture, and a Sudden Robotics Hype
- Links for the day
- Gemini Links 31/08/2025: Reviewing Netsurf and Slightly Less Historic Ada Design
- Links for the day
- IBM Has Taken Control of GNOME
- Don't expect a successor to be found any time soon
- Links 31/08/2025: Google Gmail Data Breach and LF Puff Pieces for Pay
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, August 30, 2025
- IRC logs for Saturday, August 30, 2025
- This is What Google News Has Become
- Moments ago