Eye on Security: Vista 7 is 'Secure', They Promised
- Dr. Roy Schestowitz
- 2010-11-30 21:34:07 UTC
- Modified: 2010-11-30 21:34:07 UTC
Summary: Vista 7 -- just like Vista and its processors -- is still Swiss cheese based on the latest news
●
Breaking That Other OS
Yet another means of exploiting that other OS has been demonstrated by Sophos. An ordinary user can gain complete control of the system whether it is XP, Vista, “7ââ¬Â³ etc. simply by running some code that tweaks a key in the registry. A workaround is to create a new key to block users from changing keys in the registry… Duh… How’s that for backwards compatibility?
This is another demonstration that M$ has created a monster running on nearly every PC on the planet that invites compromise. Now, hundreds of millions of users will have to do some dance with updates or tweak the registry themselves to do something that M$ neglected to do many years ago.
●
'Nightmare' kernel bug lets attackers evade Windows UAC security
Microsoft is investigating reports of an unpatched vulnerability in the Windows kernel that could be used by attackers to sidestep an important operating system security measure.
One security firm dubbed the bug a potential "nightmare," but Microsoft downplayed the threat by reminding users that hackers would need a second exploit to launch remote attacks.
●
Newly discovered Windows kernel flaw bypasses UAC
Last week an exploit for a Windows kernel flaw was published by an unknown source. Presumably as a joke, details of the flaw, along with proof-of-concept code, were published on Code Project. Code Project is a programmer peer support community, containing many tutorials and useful snippets of code to assist developers. Malware developers are not the usual target audience for posts made to the site, and so perhaps unsurprisingly, the article has been removed (though is mirrored here).
The flaw is a privilege escalation vulnerability. Anyone who can run code on a Windows system can elevate her privileges to the highest level, and accordingly install back doors, compromise sensitive data, and so on. The flaw lies in a critical Windows driver called win32k.sys. The driver inappropriately handles certain data stored in the registry—data that is stored on a per-user basis, and hence accessible to any unprivileged program. The proof-of-concept code uses this flaw to elevate the privileges of the user running the demo code; it could just as well be used to install a back door or other malware.
Recent Techrights' Posts
- Corruption is a Reality, It's Not a Dirty or a Strong Word
- Corruption is a topic some newspapers shy away from
- Rosanna Yuen & GNOME community triple tricked
- Reprinted with permission from Daniel Pocock
- IBM Layoffs Not Done, Terminations of Staff in India, Brazil, and Mexico Reported
- This hopefully answers questions such as, "do the layoffs only impact US and Canada?"
-
- Our Site Search Increases Our Editorial and Informational Independence
- Implementing our search facility is a long-term investment
- Advocates of GNU/Linux and the Uphill Battles Behind Us
- GNU/Linux felt like "activism" 20 years ago. Now it's mainstream.
- Cybersecurity Means Real Security, Not Back Doors
- Standing our ground on technology and cybersecurity is an uncompromisable stance
- Links 08/11/2025: Disinformation Crisis, Denmark Recognises Threats Associated With Social Control Media
- Links for the day
- The Free Software Foundation (FSF) is Besieged for the Times It Does the Right Things
- As that upsets rich people's interests (and they were, at times, sponsors)
- Links 08/11/2025: Technical and Financial GAFAM Woes and Arrests of Journalists by Despots
- Links for the day
- Like SUSE, IBM Red Hat Seems to be Using LLM Slop to Write Fake (Bot-Generated) Blog Posts
- IBM Red Hat keeps promoting slop
- How German Media Covered Cocainegate at The European Patent Office (EPO)
- At some point we'll ask that same press to revisit the issue and this time comment on the EPO connection
- Our Launch of Techrights Search Has Been Successful (So Far)
- There are about 50,000 articles indexed there, going 19+ years back
- Daniel Pocock Explains Social Engineering in Debian and Other Communities Increasingly Controlled by "Barons"
- Communities are not corporations
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, November 07, 2025
- IRC logs for Friday, November 07, 2025
- Adrian & Diana von Bidder-Senn, Debian: detailed history of a death
- Reprinted with permission from Daniel Pocock
- Crypto AG tricked ETH Zurich student internship
- Reprinted with permission from Daniel Pocock
- An Old Story of Fraud at the EPO in the Netherlands (and How the Dutch Government Facilitated It)
- We've already mentioned several other scandals where the the Dutch government engaged in fraud and passive corruption
- Voicing Concerns About European Patent Office (EPO) in Rijswijk
- The report is dated yesterday
- Gemini Links 08/11/2025: KeePassRX and Pluribus
- Links for the day
- Slopwatch: Brian Fagioli Targets "Linux" With LLMs, Google News Helps Blame "Linux" for Amazon WorkSpaces Flaws
- Tonight's slopfest
- Gemini Links 07/11/2025: Switzerland, k3s, and Privacy
- Links for the day
- Links 07/11/2025: Software Patents Squashed, Stock Markets Wobble Over Slop Uncertainties
- Links for the day
- A 19th Anniversary and High-Impact Exclusives
- The end of 2025 will be very difficult for EPO management
- The Register MS, Payroll First
- GNU/Linux is a growing platform
- Links 07/11/2025: US Government Shutdown Imperils Critical Functions, Slop in "AI" Clothing Debunked Some More, Bubble's Implosion Ongoing/Imminent According to Experts
- Links for the day
- Gemini Links 07/11/2025: No Goodbyes, Homelab, Mouse Keys / Pointer Keys
- Links for the day
- 12 Years for Justice is Far Too Slow (and More People, Especially Women, Are Hurt)
- Why do police departments and legal systems fail to protect women?
- Before Freenode Collapsed Its Staff (the People Who Now Run Libera.Chat) Were Censoring/Silencing Some Free Software Supporters
- We still have this issue in the Free software community
- Freenode and irc.com Are Still Around
- It emulates retro terminals
- We Don't Compete, We Analyse and Report
- Principles are so much better than money and they're something money can never acquire
- Red Hat is Also Laying Off Staff in India
- Red Hat is a dishonest company
- All We Want to See is Any Form of Accountability in Europe's Largest Institutions
- Because people at the top of institutions should never be above the law!
- Finding Recent Talks of Richard Stallman
- We already have many pages, documents, and media files. Organising them and helping people find them is the next Big Task.
- Richard Stallman First Speaker at Ethereum Cypherpunk Congress the Weekend After This Coming Weekend
- He'll be speaking over the Net
- Diversity at Red Hat
- Remember to judge corporations by their actions, not some Web pages with words in them
- First the Python Software Foundation (PSF) Attacked Its Most Productive Volunteers. Now It Attacks Its Funding Sources.
- The U.S. National Science Foundation (NSF) rejected by PSF
- News of Substance About the EPO's Substance Abuse (Cocaine)
- EPO Cocaine Chronicles - link to archived BILD article and photos
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, November 06, 2025
- IRC logs for Thursday, November 06, 2025
- On Midlife Crises
- Focus on the sabotage, not politics
- Hallmark of Fake News: "Single-digit" (Percentage) and 1% Isn't the Same Thing
- apparently "rebalancing" is the new layoffs euphemism
- Links 07/11/2025: Patent Trolls Target Germany, Celebrities Visit Ukraine
- Links for the day
- Misinformation/Disinformation Disguised as Information About GNU General Public Licenses (GNU GPL) Usage
- GPL-type licences (reciprocal obligations) remain dominant
- Slopwatch: LinuxSecurity, Brian Fagioli, and Google News Boosting WebProNews (All Slopfarms)
- Those slopfarms just saturate the Web with misinformation and mindless chaff
- Techrights and Tux Machines at Over 40
- 19 years of Techrights and 21+ years of Tux Machines
- IBM Mass Layoffs This Week Not Limited to North America, Red Hat Staff Terminated
- Do not relocate for a company that sees you as nothing but a number or a "human resource"
- Coming Soon: More Proof of Cocaine Use at Europe's Second-Largest Institution
- Stay tuned
- Entering Our 20th Year
- ...and still looking for answers
- Mailing lists vs Discourse forums: open source communities or commodities?
- Reprinted with permission from Daniel Pocock
- Links 06/11/2025: "Component Abuse Challenge", Google Play Store Deemed Too Monopolistic
- Links for the day
- Microsoft and Microsoft GitHub (and Rust @ Microsoft GitHub) the Future of Ubuntu, They Want the Same for Debian
- Ubuntu is not the place to find freedom
- Richard Stallman Was Right About LLM-based Chatbots
- the passing fad, LLM-based chatbots
- IBM Has Not Been Good for IBM's Red Hat (Which Microsoft Also Attempted to Buy)
- GAFAM or GIAFAM are not a force for good
- Taking Back Control Over Technology We Purchase (Study, Modify, Enhance, and More)
- "The war on general-purpose computing continues
- Links 06/11/2025: EFF Wants New Executive Director, Microsoft's Azure Falls Over Again
- Links for the day
- All Set for Tomorrow
- Techrights waves
- The Corporate Media Carries on With Patently Phony and Misleading Narrative About IBM's Mass Layoffs
- Instead of rightly alleging business failure or commercial (leadership's) weakness it is offloading blame to some mindless buzzwords
- IBM Isn't Hiring Based on Age Groups. It Still Hires Based on Salary Expectations.
- It is not about the skills available, it's about the expected cost of labour
- Estimating the Scale of IBM's Mass Layoffs This Week
- there is no denying that the IBM layoffs are vast
- Telling Our Story as Victims of Online Abuse
- This post will not mention any names
- Claim That EPO Quotas Brought Corruption and Mischief to Europe's Second-Largest Institution
- Nowadays corruption is the norm at the EPO and there is even rampant substance abuse among the people who run the Office
- Rust's "Memory Safety" Talking Point Ought to be Discarded in Light of Fil-C
- new memory-safe C/C++ compiler
- Claim That IBM Has Another 8 Days to Lay Off 'Expensive' Staff
- The consensus in comments we see is, IBM is a terrible place to work in, treatment of its workers is appalling, it's utterly foolish to relocate in an effort to retain a job at IBM, and it's foolish to join the company in the first place
- Science Demands Facts, Not Dogma
- Saying that restricted hardware is not secure hardware should be common sense
- Site Anniversary is Tomorrow
- The celebrations might delay our EPO series somewhat
- Launching Techrights Search
- New search interface and locally hosted back end
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, November 05, 2025
- IRC logs for Wednesday, November 05, 2025