Microsoft says RIP Windows XP AutoRun for USB

Powered by SC Magazine
 

The feature that became an attack vector.

Microsoft has finally decided to push out a Windows update that should stop attempts to exploit AutoRun with a USB stick.

AutoRun is a feature of the Windows operating system that fires up any program once a USB or CD/DVD is inserted into a computer.

In recent years hackers have increasingly turned to AutoRun, which permits programmers to deliver instructions via Autorun.inf files to run programs without first gaining user permission.

The problem for Microsoft was that while the obvious solution was to disable AutoRun, it was considered a legitimate feature, which happened to be exploited by the Conficker worm, Rimecud and Taterf.

"AutoRun isn't an accident -- it's by design, and as I mentioned we care about the very real positive uses of the feature. In other words, in a very real sense, it's not a bug, it's a feature," said Adam Shostack, a Microsoft security program manager.

So Microsoft wasn't calling its Windows Update a "security update" but rather an "Important, non-security update" which effectively disabled AutoRun.

The feature remained in Windows 7 but Microsoft claimed to have largely addressed AutoRun abuse. One of its reasons for issuing the "non-security update" was that it found that Windows XP users were 10 times more likely to get infected when faced with such an attack.

First introduced in Windows 95, the feature has caused security professionals frustration. In 2008, infected digital picture frames exploited the feature and while it was possible to disable AutoRun, doing so was not an easy task.

At last year's AusCERT security conference IBM accidentally issued delegates a thumb drive which exploited AutoRun.

Copyright © iTnews.com.au . All rights reserved.


Microsoft says RIP Windows XP AutoRun for USB
 
 
 
Top Stories
Taking the fight to the disruptors
Seven West Media's new chief digital officer, Clive Dickens, says if a media company as historic as Disney can take on the new media landscape, then so can he.
 
AGL appoints three new technology chiefs
Trio of former CFOs take over tech.
 
M2 makes $1.6bn play for iiNet
Challenges TPG's March takeover offer.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Small business win in a budget with 'fair' savings: Abbott
Apr 17, 2015
Tony Abbott has reaffirmed that the government’s aim is “always to get taxes ...
Xero now includes an inventory function built-in
Mar 26, 2015
Xero has added inventory and other major new features to the latest release of its cloud ...
Apple reveals its new MacBook
Mar 13, 2015
Replacing the MacBook Air as Apple's thinnest laptop, the new MacBook comes packed with features.
Xero has released a new version of its app for the iPad
Mar 6, 2015
iPad-wielding Xero users can now take advantage of a new version of the iOS app for the cloud ...
Microsoft is offering Azure for Disaster Recovery to Australian SMBs
Feb 10, 2015
If you haven't talked to your IT provider about disaster recovery, it might be worth discussing ...
Latest Comments
Polls
Do you support the Government's data retention scheme?

   |   View results
Yes
  11%
 
No
  89%
TOTAL VOTES: 2570

Vote