Microsoft says RIP Windows XP AutoRun for USB

Powered by SC Magazine
 

The feature that became an attack vector.

Microsoft has finally decided to push out a Windows update that should stop attempts to exploit AutoRun with a USB stick.

AutoRun is a feature of the Windows operating system that fires up any program once a USB or CD/DVD is inserted into a computer.

In recent years hackers have increasingly turned to AutoRun, which permits programmers to deliver instructions via Autorun.inf files to run programs without first gaining user permission.

The problem for Microsoft was that while the obvious solution was to disable AutoRun, it was considered a legitimate feature, which happened to be exploited by the Conficker worm, Rimecud and Taterf.

"AutoRun isn't an accident -- it's by design, and as I mentioned we care about the very real positive uses of the feature. In other words, in a very real sense, it's not a bug, it's a feature," said Adam Shostack, a Microsoft security program manager.

So Microsoft wasn't calling its Windows Update a "security update" but rather an "Important, non-security update" which effectively disabled AutoRun.

The feature remained in Windows 7 but Microsoft claimed to have largely addressed AutoRun abuse. One of its reasons for issuing the "non-security update" was that it found that Windows XP users were 10 times more likely to get infected when faced with such an attack.

First introduced in Windows 95, the feature has caused security professionals frustration. In 2008, infected digital picture frames exploited the feature and while it was possible to disable AutoRun, doing so was not an easy task.

At last year's AusCERT security conference IBM accidentally issued delegates a thumb drive which exploited AutoRun.

Copyright © iTnews.com.au . All rights reserved.


Microsoft says RIP Windows XP AutoRun for USB
 
 
 
Top Stories
ATO shaves $4m off IT contractor panel
Reform cuts admin burden, introduces KPIs.
 
Turnbull introduces data retention legislation
Still no definition of metadata to be stored.
 
Crime Commission prepares core systems overhaul
Will replace 30 year-old national criminal database.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Optus expands 4G coverage
Oct 10, 2014
If you rely on an Optus phone for work you might be interested to know that there are now 200 ...
Microsoft Office is now free for some charities
Oct 10, 2014
Microsoft has announced that eligible Australian non-profit organisations and charities can now ...
Vodafone lights up 4G in Adelaide
Oct 9, 2014
Live and work in Adelaide? Vodafone has switched on its 4G network in the city and suburbs.
Next year tradies will be able to take payments using ingogo
Oct 3, 2014
Ingogo is going to provide a card payment service for Xero users.
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  27%
 
Sourcing and strategy
  13%
 
IT infrastructure (servers, storage, networking)
  21%
 
End user computing (desktops, mobiles, apps)
  14%
 
Software development
  25%
TOTAL VOTES: 437

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  54%
 
No
  46%
TOTAL VOTES: 210

Vote