Microsoft says RIP Windows XP AutoRun for USB

Powered by SC Magazine
 

The feature that became an attack vector.

Microsoft has finally decided to push out a Windows update that should stop attempts to exploit AutoRun with a USB stick.

AutoRun is a feature of the Windows operating system that fires up any program once a USB or CD/DVD is inserted into a computer.

In recent years hackers have increasingly turned to AutoRun, which permits programmers to deliver instructions via Autorun.inf files to run programs without first gaining user permission.

The problem for Microsoft was that while the obvious solution was to disable AutoRun, it was considered a legitimate feature, which happened to be exploited by the Conficker worm, Rimecud and Taterf.

"AutoRun isn't an accident -- it's by design, and as I mentioned we care about the very real positive uses of the feature. In other words, in a very real sense, it's not a bug, it's a feature," said Adam Shostack, a Microsoft security program manager.

So Microsoft wasn't calling its Windows Update a "security update" but rather an "Important, non-security update" which effectively disabled AutoRun.

The feature remained in Windows 7 but Microsoft claimed to have largely addressed AutoRun abuse. One of its reasons for issuing the "non-security update" was that it found that Windows XP users were 10 times more likely to get infected when faced with such an attack.

First introduced in Windows 95, the feature has caused security professionals frustration. In 2008, infected digital picture frames exploited the feature and while it was possible to disable AutoRun, doing so was not an easy task.

At last year's AusCERT security conference IBM accidentally issued delegates a thumb drive which exploited AutoRun.

Copyright © iTnews.com.au . All rights reserved.


Microsoft says RIP Windows XP AutoRun for USB
 
 
 
Top Stories
Photos: iTnews Benchmark Awards countdown begins
Just a few days left until entries close for 2014.
 
Australian Govt to rethink cyber security strategy
Six-year old policy to be refreshed.
 
The failure of the antivirus industry
[Blog post] Insights from AVAR 2014.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
More 4G from Optus in Darwin
Nov 21, 2014
Click to see where Optus has expanded coverage to the suburbs near Darwin.
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 1072

Vote