Friday, February 02, 2007

Vista UAC Triggers

Ed Bott responded to a reader's question about UAC Account triggers with a quote from his recently published book, Windows Vista Inside Out. The question came from Ed's earlier post, which I had been planning on pointing out anyway. So, while you're at it, read the articles and the comments in both of Ed's articles, linked below. Great stuff, Ed!

UAC Triggers:

The types of actions that require elevation to administrator status (and therefore display a UAC elevation prompt) include those that make changes to system-wide settings or to files in %SystemRoot% or %ProgramFiles%. Among the actions that require elevation:

  • Installing and uninstalling applications
  • Installing device drivers
  • Installing ActiveX controls
  • Installing Windows Updates
  • Changing settings for Windows Firewall
  • Changing UAC settings
  • Configuring Windows Update
  • Adding or removing user accounts
  • Changing a user’s account type
  • Configuring Parental Controls
  • Running Task Scheduler
  • Restoring backed-up system files
  • Viewing or changing another user’s folders and files

Within Windows Vista, you can identify in advance many actions that require elevation. A shield icon next to a button or link indicates that a UAC prompt will appear.



References:

Thursday, February 01, 2007

Issue regarding Windows Vista Speech Recognition

Following is the first part of my post at the Windows Connected forum from last night on the Windows Vista Speech Recognition "issue":
As reported on the MSRC Blog,
"An issue has been identified publicly where an attacker could use the speech recognition capability of Windows Vista to cause the system to take undesired actions. While it is technically possible, there are some things that should be considered when trying to determine what the threat of exposure is to your Windows Vista system."

This is another of those situations where it is "technically possible", however there are a lot of variables that would need to be met in order for an attack to be successful. There are those who will look for absolutely any angle they can find to question the security of Windows Vista.

There have been numerous repeats across the Internet today about this "issue". What I find most disturbing is the manner in which various services are headlining it; i.e., "Talking security vulnerability in Vista", "Hackers can whisper sweet nothings into Vista's ear", "Vista has speech recognition hole", and more of a similar nature.

Let's break the MSRC post down a bit and read more carefully what it would take for such an attack to be successful:

  • the targeted system would need to have the speech recognition feature previously activated and configured
  • the system would need to have speakers and a microphone installed and turned on
  • the exploit scenario would involve the speech recognition feature picking up commands through the microphone such as “copy”, “delete”, ”shutdown”, etc. and acting on them
  • the commands would be coming from an audio file that is being played through the speakers

Even if all of the above was likely and the user was not there to turn off the microphone or speakers or shutdown the computer, note the sentences below, particularly the two in bold:

  • It is not possible through the use of voice commands to get the system to perform privileged functions such as creating a user without being prompted by UAC for Administrator credentials.
  • The UAC prompt cannot be manipulated by voice commands by default.
  • There are also additional barriers that would make an attack difficult including speaker and microphone placement, microphone feedback, and the clarity of the dictation.

Know what I think? More sensationalism by the press and much ado about nothing.

Phishing News and Updates

Phishing News

Certainly by now everyone knows that IE7, Firefox and Opera browsers all have phishing filters. That is not to say that the browsers will catch all "phishes" or that, for varying reasons, you have the most recent browser release that includes the phishing filter. Of course if your reason for not updating your browser is because you haven't gotten around to it, please make the time. In addition to providing added features, the updated browsers are infintely more secure.

So, what happens to all those phishes? If you delete the phish from your email, they continue. However, as I have written a number of times before, if you submit the phish to http://www.castlecops.com/pirt, you will do your part in helping to bring the phishing site down.

Learn more about the effect the Castle Cops PIRT Team has had in preventing more than $22 million worth of fraudulent credit card charges since its inception last year in Brian Kreb's article, In Praise of Phish Fighters. Also included is information about Castle Cops 5th Birthday Celebration sweepstakes give-away of more than $130,000 worth of security software and tools to Castle Cops forum members. Contest details and entry are available at CastleCops.

Update 04Feb07: I've said many times how much I respect Alex Eckelberry. He truly is a class act! Read Alex Recognizing Paul and Robin Laudanski.
(trackback)

IE7 Phishing Performance Filter Update

As I reported in December, some people have experienced high CPU usage with the IE7 Phishing Filter on pages that contain multiple frames or when multiple frames are navigated simultaneously (i.e., opening multiple tabs containing pages with frames).

The IE Team announced the release of the Phishing Filter update to Windows Update for Windows Vista users on January 29. It is to be added to Windows Update for Windows XP and Windows Server 2003 users this month. Versions are available for all systems at Knowledge Base Article 928089.