Related Links

Related Stories

  • Batten down the hatches
    Due to the horrifying quantity of vulnerabilities, and often limited time and budget, application and database security can be quite a headache. Limiting privileges and access, however, is a good place to start, finds Danny Bradbury
  • Information security threats in H1 2009: malware and rogue security software
    Microsoft has just released its Security Intelligence Report volume 7 (SIRv7) for the first half (H1) of 2009 exploring the most prevalent information security threats - malware and rogue security software.
  • The black art of digital forensics
    What makes a good digital forensics specialist? Steve Gold looks at some of the latest applications and investigates how the forensic investigator’s role has evolved in order to comply with changing customer priorities
  • Coughs and sneezes spread diseases
    Mobile devices can keep business ticking over when human diseases strike, but the devices have viruses of their own, finds William Knight
  • Zero Day of the Dead
    The data load that has accompanied the globalization of trade would make even Atlas stagger. And that’s without the added burden of counter-terrorisAs you read this, zombie programs are flitting across the internet like a pestilence to infect and drain the life from innocent computer systems. Yet, for all the aggravation and grief they cause, you may never know you are part of a global invasion of the system snatchers, says William Knight. Unless…

News

US-CERT warns Microsoft Windows autorun off advice is flawed

22 January 2009

The US Computer Emergency Readiness Team (US-CERT) has warned Microsoft's advice on how to turn off the autorun option within Windows is not effective.

 

The autorun option is being used by a number of worm attacks to trigger a malware infection. As a result of this, Microsoft has issued an advisory to IT managers and other interested parties on how to turn off the autorun option.
The problem, says US-CERT officials, is that Microsoft's advice on changing the Autorun and NoDriveTypeAutorun registry values is ineffective as setting the Autorun registry value to 0 - as the software giant is recommending - will not prevent newly connected devices from automatically running program code specified in the
Autorun.inf file.
Perhaps worse, Infosecurity notes, the registry changes will disable Media Change Notification messages, which may prevent Windows from detecting when a CD or DVD is changed.
Microsoft says that setting the NoDriveTypeAutorun registry value to 0xFF "disables Autoplay on all types of drives."
US-CERT, however, reports that even with this value set, Windows can execute arbitrary program code when the user clicks the icon for the device in Internet Explorer.
This means that malware authors and hackers can place an Autorun.inf file on a device to automatically execute arbitrary code when the device is connected to a Windows system.
US-CERT also advises that code execution can also take place when the user attempts to browse to the software location with Internet Explorer.

 

 

This article is featured in:
Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.