Eye on Security: Vista 7 is 'Secure', They Promised
- Dr. Roy Schestowitz
- 2010-11-30 21:34:07 UTC
- Modified: 2010-11-30 21:34:07 UTC
Summary: Vista 7 -- just like Vista and its processors -- is still Swiss cheese based on the latest news
●
Breaking That Other OS
Yet another means of exploiting that other OS has been demonstrated by Sophos. An ordinary user can gain complete control of the system whether it is XP, Vista, “7ââ¬Â³ etc. simply by running some code that tweaks a key in the registry. A workaround is to create a new key to block users from changing keys in the registry… Duh… How’s that for backwards compatibility?
This is another demonstration that M$ has created a monster running on nearly every PC on the planet that invites compromise. Now, hundreds of millions of users will have to do some dance with updates or tweak the registry themselves to do something that M$ neglected to do many years ago.
●
'Nightmare' kernel bug lets attackers evade Windows UAC security
Microsoft is investigating reports of an unpatched vulnerability in the Windows kernel that could be used by attackers to sidestep an important operating system security measure.
One security firm dubbed the bug a potential "nightmare," but Microsoft downplayed the threat by reminding users that hackers would need a second exploit to launch remote attacks.
●
Newly discovered Windows kernel flaw bypasses UAC
Last week an exploit for a Windows kernel flaw was published by an unknown source. Presumably as a joke, details of the flaw, along with proof-of-concept code, were published on Code Project. Code Project is a programmer peer support community, containing many tutorials and useful snippets of code to assist developers. Malware developers are not the usual target audience for posts made to the site, and so perhaps unsurprisingly, the article has been removed (though is mirrored here).
The flaw is a privilege escalation vulnerability. Anyone who can run code on a Windows system can elevate her privileges to the highest level, and accordingly install back doors, compromise sensitive data, and so on. The flaw lies in a critical Windows driver called win32k.sys. The driver inappropriately handles certain data stored in the registry—data that is stored on a per-user basis, and hence accessible to any unprivileged program. The proof-of-concept code uses this flaw to elevate the privileges of the user running the demo code; it could just as well be used to install a back door or other malware.
Recent Techrights' Posts
- 99.99% Uptime in First Half of 2025
- Since January there was only one noticeable outage
- When People Call a Best/Close Friend of Bill Gates a "Serial Rapist"
- Good thing that the Linux Foundation keeps the "Linux" trademark ("Linux Mark") clean
- Microsoft Bankruptcy in Russia, Shutdown in Pakistan, What Next?
- It seems possible that in 2025 alone Microsoft will have laid off over 50,000 workers
- What Matters More Than "Market Share"
- The goal is freedom, not "market share"
- Credit Suisse collapse obfuscated Parreaux, Thiébaud & Partners scandal
- Reprinted with permission from Daniel Pocock
- UK Media Under Threat: Cannot Report on Data Breach, Cannot Report on Microsoft Staff Strangling Women
- The story of super injunction (in the British media this week, years late)
-
- Slopwatch: LinuxSecurity.com Slopfarm and Slopfarms Propped Up by Google News
- "As LLM slop is foisted onto the WWW in place of knowledge and real content, it now gets ingested and processed by other LLMs, creating a sort of ouroboros of crap."
- Links 18/07/2025: Weather Events and Health Hazards
- Links for the day
- Microsoft's All-Time Low in Finland
- Microsoft is in a freefall
- Security: Shane Wegner & Debian statement of incompetence
- Reprinted with permission from Daniel Pocock
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, July 17, 2025
- IRC logs for Thursday, July 17, 2025
- Gemini Links 17/07/2025: "Goodreads for Gemini" and Defence of "The Small Web"
- Links for the day
- Links 17/07/2025: Anger and Morale Issues at Microsoft, Wars and Conflicts Get Digital
- Links for the day
- CALEA / CALEA2 is the Real Problem, Not Chinese Operatives Exploiting CALEA / CALEA2 (as Any Other Nation Can)
- CALEA / CALEA2 is more of a front door than a back door
- Nils Torvalds and Anna "Mikke" Torvalds (née Törnqvis) Hopefully Use GNU/Linux by Now
- "Torvalds Family Uses Windows, Not Linus’ Linux"
- Attack of the Slopfarms
- FUD-amplifying bots with slop images, slop text (LLM slop)
- Not My Problem, I Don't Care
- Context/inspiration: Martin Niemöller
- Honest Journalism About the European Patent Office Ceased to Exist After SLAPPs and Bribes to the Media
- The EPO is basically a Mafia
- Life Became Simpler When I Stopped Driving and I Don't Miss Driving When I See "Modern" Cars
- Gee, wonder why car sales have plummeted...
- Why I Believe Brett Wilson LLP and Its Microsoft Clients Are All Toast
- So far our legal strategy has worked perfectly
- EPO Jobs Are Very Toxic and Bad for One's Health
- Health first, not monopolies
- Response to Ryo Suwito Regarding the Four Freedoms
- the point of life isn't to make more money
- Microsoft's Morale Circling Down the Drain
- Or gutter, toilet etc.
- Tech Used to be Fun. To Many of Us It's Still Fun.
- You can just watch it from afar and make fun of it all
- Links 17/07/2025: "Blog Identity Crisis" and Openwashing by Nvidia
- Links for the day
- Greffiers and the US Attorney of the Serial Strangler From Microsoft
- The lawsuit can help expose extensive corruption in the American court system as well
- The People Who Promoted systemd in Debian Also Promote Wayland
- This is not politics
- Victims of the Serial Strangler From Microsoft, Alex Balabhadra Graveley, Wanted to Sue Him But Lacked the Funds (He Attacked Their Finances)
- Having spoken to victims of the Serial Strangler From Microsoft
- Links 17/07/2025: Science, Hardware, and Censorship
- Links for the day
- Gemini Links 17/07/2025: Staying in the "Small Web" and Back on ICQ
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, July 16, 2025
- IRC logs for Wednesday, July 16, 2025
- Under the Guise of "MIT Technology Review Insights" the Site MIT Technology Review Posts Corporate Spam as 'Articles'
- Some of the articles aren't even articles but 'hit pieces' against Free software and some are paid advertisements
- Brett Wilson LLP Has Track Record in Scam Coin Cases (e.g. Craig Wright and More), Now It Works for 'Crypto' Scam Purveyors
- But wait, it gets worse
- Exclusive: corruption in Tribunals, Greffiers, from protection rackets to cat whisperers
- Reprinted with permission from Daniel Pocock
- Will Brett Wilson LLP Handle Its Own Winding Up Petition or be Struck Off for Overt Abuse of Process?
- Today we sue not only the first Microsofter
- Links 16/07/2025: Chip Bans and Microsoft’s “Digital Escort” Program
- Links for the day
- Ubuntu Becomes Microsoft GitHub, Based on Decision Made by British Army Officer
- You're hopeless, Canonical
- Revolving Doors: One Day You're a Judge, the Next Day You're an Attorney Paying Public Officials and Working for Violent and Dangerous Microsoft Employees
- how the US justice system works
- Sharing Code and Recipes
- It helps explain the triviality of software freedom
- Slopwatch: Noise, Plagiarism and Even Fear, Uncertainty, Doubt/Fear-mongering/Dramatisation
- What are we meant to do to prevent a false association or misleading connotations? Game the LLMs? No. Boycott slopfarms.
- How Many Women Has Microsoft's Alex Balabhadra Graveley Already Strangled and Where Does That End?
- If you too are a victim of this man and wish to share information, contact us
- Gemini Links 16/07/2025: BaseLibre Numerical System and Simple Web Browsing with TLS
- Links for the day
- Links 16/07/2025: Fascist Slop Takes "Intelligence" Clothing, New Criminal Case Against MElon
- Links for the day
- "We Might Save Somebody's Life"
- I follow the example of my father
- Why I am Suing the Serial Strangler From Microsoft, Alex Balabhadra Graveley, in the UK High Court This Week
- Out of respect to the process and to the Court, I shall not share any pertinent details about the case
- Links 16/07/2025: China’s Economy Grows Steadily, France Takes Action Regarding Harm to Children by GAFAM and Fentanylware (TikTok)
- Links for the day
- It is Not About Politics
- Beware the people who try to make this about politics
- Good Journalism Saves Lives
- a shocking number of women die or get seriously hurt every day due to violence from a partner
- Recognition of Women's Contributions to Free Software
- Being passive is not an option when bad things are happening
- Slopfarms Are Going to Perish Because Public Opinion is Changing
- Many slopfarms will simply go offline
- 19 Years of Standing Up for Justice, Equality, and Truth
- This week we shall take it up a notch
- Gemini Links 16/07/2025: Tmux and OCC25 Working TLS
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, July 15, 2025
- IRC logs for Tuesday, July 15, 2025