<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="HardwareAnalysis.Com" -->
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="">
        <title>Hardware Analysis - Vista AutoRun might leave your systems vulnerable</title>
        <description>Hardware Analysis Community Forums</description>
        <link>http://www.hardwareanalysis.com/content/topic/71244/</link>
        <image rdf:resource="http://media.hardwareanalysis.com/halogo.gif" />
       <dc:date>2008-10-07T21:44:08-05:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533952"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533337"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533325"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533324"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533318"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71244/?l=1#0"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://media.hardwareanalysis.com/halogo.gif">
        <title>Hardware Analysis</title>
        <link>http://www.hardwareanalysis.com/content/topic/71244/</link>
        <url>http://media.hardwareanalysis.com/halogo.gif</url>
    </image>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533952">
        <dc:format>text/html</dc:format>
        <dc:date>2008-04-18T18:26:16-05:00</dc:date>
        <dc:creator>McFly</dc:creator>
        <title>Re: Vista AutoRun might leave your systems vulnerable</title>
        <link>http://www.hardwareanalysis.com/content/topic/71244/?l=1#533952</link>
        <description>I always disable autorun ... I don't think I've seen it come back on it's own. :-X&lt;br /&gt;
&lt;br /&gt;
One thing I also do is, even when you have autorun disabled, double-clicking a mounted CD with autorun features will start the autorun program ... bit of a mouthful ... what I mean is, it doesn't start when you pop the disc in, it starts when you try to explore the drive -- a, &amp;quot;manual autorun,&amp;quot; if that makes any sense.&lt;br /&gt;
&lt;br /&gt;
What I do to fix that is find the autorun item for the drive in question in the MountPoints2 key in the registry, remove it, and then make those keys read-only, so the next time I pop in a disc, autorun can't add itself to a drives context menu, and double-clicking the drive takes me straight to an Explorer view.</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533337">
        <dc:format>text/html</dc:format>
        <dc:date>2008-04-11T12:50:29-05:00</dc:date>
        <dc:creator>john albrich</dc:creator>
        <title>Re: Vista AutoRun might leave your systems vulnerable</title>
        <link>http://www.hardwareanalysis.com/content/topic/71244/?l=1#533337</link>
        <description>DublinGunner said: &lt;div class=&quot;quote&quot;&gt;...I have it disabled, so any 'autoplay' type media inserted, merely invokes the pop up box...&lt;/div&gt;&lt;br /&gt;
Ideally, it doesn't even do that when it's totally disabled. Windows itself should require no user action whatsoever, nor should it display anything like popping-up a passive Explorer window. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
However, even with auto-scanning anti-malware software installed, when a medium is inserted it should also do nothing (as far as the user is concerned) unless a security problem is detected or it makes the user or an application wait until a security scan is completed. Ideally the user would have the option to either display or not display a message when an automated scan is underway.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
edit to add--&lt;br /&gt;
Re my prior post on this, I initially did think security software was contributing to the noted eventual re-activating of the auto-play &amp;quot;feature&amp;quot;, but using &amp;quot;regmon&amp;quot; I did not find any evidence this was the actual cause.</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533325">
        <dc:format>text/html</dc:format>
        <dc:date>2008-04-11T09:24:19-05:00</dc:date>
        <dc:creator>DublinGunner</dc:creator>
        <title>Re: Vista AutoRun might leave your systems vulnerable</title>
        <link>http://www.hardwareanalysis.com/content/topic/71244/?l=1#533325</link>
        <description>Funnily, I dont have this issue with my Vista install.&lt;br /&gt;
&lt;br /&gt;
I have it disabled, so any 'autoplay' type media inserted, merely invokes the pop up box asking me what I would like to do (i.e play, open folder to view files, open in program x etc)</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533324">
        <dc:format>text/html</dc:format>
        <dc:date>2008-04-11T09:24:19-05:00</dc:date>
        <dc:creator>Tam the Bam</dc:creator>
        <title>Re: Vista AutoRun might leave your systems vulnerable</title>
        <link>http://www.hardwareanalysis.com/content/topic/71244/?l=1#533324</link>
        <description> &lt;br /&gt;
 I hate Autorun. Since I've had my very first PC, I disabled it. It p**ses me off.</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71244/?l=1#533318">
        <dc:format>text/html</dc:format>
        <dc:date>2008-04-11T08:36:13-05:00</dc:date>
        <dc:creator>john albrich</dc:creator>
        <title>Re: Vista AutoRun might leave your systems vulnerable</title>
        <link>http://www.hardwareanalysis.com/content/topic/71244/?l=1#533318</link>
        <description>I can verify this is definitely the case with WinXP Pro and XP Home up to current service packs. I have disabled autorun multiple times on several machines, including using registry hacks to do so.&lt;br /&gt;
&lt;br /&gt;
After doing so, I have tested the machines with multiple devices and media, and always verified the autorun &amp;quot;feature&amp;quot; was 100% disabled.&lt;br /&gt;
&lt;br /&gt;
Invariably after some amount of time has passed (days/weeks) the autorun &amp;quot;feature&amp;quot; is somehow mysteriously restored on 100% of the machines (I don't use auto-update so that's not causing the change, restore points weren't used, and I closely monitor what's happening on these machines)&lt;br /&gt;
&lt;br /&gt;
As yet I have found no explanation for this behavior.</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71244/?l=1#0">
        <dc:format>text/html</dc:format>
        <dc:date>2008-04-11T04:29:36-05:00</dc:date>
        <dc:creator>TWolfe</dc:creator>
        <title>Vista AutoRun might leave your systems vulnerable</title>
        <link>http://www.hardwareanalysis.com/content/topic/71244/?l=1#0</link>
        <description>This is from WINDOWS SECRETS. I'm just passing along information.&lt;br /&gt;
&lt;br /&gt;
Disabling AutoRun still leaves you open to attack &lt;br /&gt;
&lt;br /&gt;
  By Mark Joseph Edwards (Windows Secrets staff writer)&lt;br /&gt;
&lt;br /&gt;
The worst kind of security bug is one that Microsoft probably won't be fixing any time soon.&lt;br /&gt;
&lt;br /&gt;
This week, I tell you about an annoying security problem in which Windows Vista fails to disable its AutoRun and AutoPlay features, even though you think you've got these two security risks under control.&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
According to an advisory published by US-CERT, Vista might not truly disable its AutoRun and AutoPlay features when you configure the operating system to do so. Those features kick into action whenever you insert a CD or DVD.&lt;br /&gt;
&lt;br /&gt;
On a typical system, if a CD, a DVD, or a U3-enabled USB drive includes an AutoRun file — or can be detected by Vista as AutoPlay media — Vista automatically launches a corresponding application to view or play the media. That behavior can pose a serious security problem if you insert a medium that contains malware.&lt;br /&gt;
&lt;br /&gt;
To protect against that possibility, Microsoft provides ways to disable AutoRun and AutoPlay for various devices. However, according to the US-CERT advisory, &amp;quot;Windows Vista may [leave] some AutoPlay enabled, even though the Group Policy Editor and associated registry values indicate otherwise.&amp;quot; This, of course, means that an attack would still be possible.&lt;br /&gt;
&lt;br /&gt;
As far as I know, Microsoft has not issued any kind of patch for this problem. Worse, I'm not even sure that the company will issue a patch. (AutoRun and AutoPlay are considered important and desirable features.)&lt;br /&gt;
&lt;br /&gt;
US-CERT's advisory, however, does offer some information that might help you reduce your vulnerability. One workaround involves creating a .reg file and loading it into the Windows Registry. I consider the other workarounds that are listed by US-CERT to be problematic and less reliable.&lt;br /&gt;
&lt;br /&gt;
Windows Secrets associate editor Scott Dunn warned last year about the problem with AutoRun appearing to be disabled (in both Vista and XP) but actually still allowing attacks. He prescribed exactly the same .reg workaround that US-CERT is now proposing, but he provided far greater detail. See Scott's Nov. 8, 2007, column for the complete story.&lt;br /&gt;
&lt;br /&gt;
To read US-CERT's analysis, see its vulnerability note 889747.&lt;br /&gt;
&lt;br /&gt;
Just thought you might want to know.&lt;br /&gt;
Try this link,it explains various problems &lt;a class=&quot;ext&quot; href=&quot;/action/r/http://www.kb.cert.org/vuls/id/889747&quot; target=&quot;_blank&quot;&gt;http://www.kb.cert.org/vuls/id/889747&lt;/a&gt;</description>
    </item>
</rdf:RDF>
