Networking
Security
Telco/ISP
Storage
Hardware
Software
Oddware
Strategy
Finance
Training & Development
Login
|
Join iTnews
|
Sitemap
|
RSS
Reviews
|
Galleries
|
Events
|
Net Seminars
|
Whitepapers
|
Downloads
|
Newsletter
|
Videos
Home
>
News
>
Technology
>
Software
>
Hacker highlights gaping Vista security hole
Software
Hacker highlights gaping Vista security hole
Related Articles
Top 10 themes from RSA Security Conference
White House turns to hacker for security advice
Sophos Security Suite SBE 2.5
Kaspersky Small Office Security
Breaking Stories
Microsoft denies Windows 7 battery problems
Ex-Intel executive owns up to insider trading
Optus to boost HFC network up to 100 Mbps
Microsoft launches Surface, unveils partners and customers
Opinion: Webjet brings 'cloud' claims back down to earth
Feb 19, 2007 9:52 AM
Tags:
hacker
|
highlights
|
gaping
|
vista
|
security
|
hole
Microsoft tries to play it down.
White hat hacker Joanna Rutkowska claims to have discovered a gaping hole in the User Account Control (UAC) security functionality of Windows Vista.
Microsoft admitted that many users ran Windows XP constantly using the admin account, which provides unfettered access to all parts of the system.
To help mitigate the security risks, Vista runs in a normal user account by default and provides pop-up confirmation dialogues when it needs to perform admin functions, such as modifying system files.
Rutkowska discovered that when Vista detects that the user is running an installation file it kicks into full admin mode.
If a user wishes to install a new program they are presented with the option either to allow the installer complete system privileges or not to run the program at all.
Rutkowska wrote on her Invisible Things blog: "That means that if you downloaded some freeware Tetris game, you will have to run its installer as administrator, giving it full access to all your file system and registry, and allowing it to load kernel drivers! Why should a Tetris installer be allowed to load kernel drivers?
"I would like to be offered a choice whether to fully trust a given installer executable [and run it as full administrator] or just allow it to add a folder in C:\Program Files and some keys under HKLM\Software and do nothing more.
"I could do that under Windows XP, but apparently I can't under Vista, which is a bit disturbing."
A few days after her posting there was a lengthy and detailed response from Mark Russinovich, a Technical Fellow at Microsoft.
Russinovich essentially admitted that, while the problem exists, it was a design choice that stemmed from the balance between security and usability.
"Because elevations and integrity levels do not define a security boundary, potential avenues of attack, regardless of ease or scope, are not security bugs, " he said.
In light of the huge security campaign surrounding Windows Vista in 2006, Rutkowska said in a follow up posting that this explanation simply is not good enough and that Microsoft should attempt to solve the problem rather than try and dismiss the issue.
Copyright © 2009 v3.co.uk
Email this
Print this
Tweet this
Send us your tips
Comments
Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Register for FREE
Or
log in
now to comment
Ads by Google
IT Whitepapers
Top Categories
Networking
Software Development
IT Management
Enterprise Applications
Storage
more technology whitepapers »
Latest Technology Jobs
Instructional Designer (Training Developer) (s15)
Informatica PowerCenter Consultants
SAP Business Analyst
Windows Server Engineer
PowerBuilder Developer - PowerBuilder, DB2, Solaris
Netbackup Storage Specialist
more technology jobs »
Top Stories
TIO website hit by malware
Weekend malware runs one new process per target machine.
Microsoft announces Azure launch date
Australia in second wave of country releases.
CBA embarks on "database-as-a-service"
Analysis: How the bank intends to save megabucks.
iiNet wins! Film industry's case torn to shreds
No "three strikes rule" for Australian ISPs
iiTrial: Judgement Day (live coverage)
Key EDS witness bought internet degree
Legal experts expect appeal in iiNet judgement
Christian Lobby buoyant on filtering after meeting Conroy
iiNet wins! Film industry's case torn to shreds
Day 20: iiNet refuses to play police for film industry
iiNet vs the film industry: Judgement day preview
Day 20: iiNet can’t vet AFACT copyright allegations
Spotlight
the topics we're following
Telstra Split
IINET vs AFACT
Cloud computing
Internet Filtering
NBN
Latest Comments
"With Optus supposedly boosting this service sounds great, record profits on mobile business ..."
on
Optus to boost HFC network up to 100 Mbps
by
Johnnnny
Feb 10, 2010 9:58 AM
"The Howard government used to provide free net-nanny software that parents could download & ..."
on
Commentary: Think B4 U waste our time and money
by
Ace
Feb 10, 2010 9:56 AM
"Digger and JL - the two biggest back-flippers in history. (Or are they they same person ?) Now ..."
on
Exetel drops infringement policy after iiNet win
by
marklara
Feb 10, 2010 9:56 AM
"Once we get past cloud computing, it will be full speed ahead to blue sky computing - although ..."
on
Opinion: Webjet brings 'cloud' claims back down to earth
by
Ace
Feb 10, 2010 9:52 AM
"Maxxi if your reading this I am pretty sure the opinion of Google far outweighs the minority ..."
on
Google cold on voluntary YouTube filtering
by
Mark D
Feb 10, 2010 9:46 AM
Plan Finder
Powered by
WhistleOut
Mobiles
Deals
Broadband
1)
HTC Magic
16 plans
2%
2)
Nokia N97
43 plans
9%
3)
Nokia E71
49 plans
1%
4)
Apple iPhone 3GS 16GB
30 plans
11%
5)
Apple iPhone 8GB
42 plans
5%
Fast Wireless BB
in Your Home
This wireless modem gives you super-fast broadband in home + free local / national calls.
Sony Deals
With Optus
Great Sony PlayStation® deals available for a limited time with Optus.
Save $50 on
iPhone 3G 8GB
3 Mobile are offering $50 off an iPhone 3G 8GB on $49 cap and above.
3 Months Free
on HTC Magic
The HTC Magic is now available on the $29 Cap from 3 Mobile with 3 months free access.
3 Months Free
on Nokia N97
Big February update - now 3 months free with Vodafone on the $59 Cap.
3 Months Free
on Nokia E71
The Nokia E71 is now available on the $29 Cap from 3 Mobile with 3 months free access.
Nokia E72 +
3 Months Free!
The Nokia E72 - new model with full keyboard and 3 months free on the $49 Cap.
3 Months Free
with 3 Mobile
Get 3 months free on Nokia E71, Samsung F480, Nokia E63 and more with 3 Mobile.
This Guy is Not
Bob. This is...
Super-fast in home wireless broadband + free local / national calls.
«
1
of
»
1)
iiNet
32 plans
5%
2)
Netspace
36 plans
11%
3)
TPG Internet
19 plans
14%
4)
Optus
33 plans
1%
5)
Telstra BigPond
30 plans
2%
Mobiles
|
Broadband
|
Credit Cards
iTnews
Polls
What is the sweet spot for Apple's entry 16GB Wi-Fi iPad?
$549
$579
$619
$649
$699
|
View results
$549
77%
$579
11%
$619
4%
$649
3%
$699
5%
TOTAL VOTES: 384
Vote
view previous polls »