Re: Windows Firewall Has A Backdoor

From: Chris Wysopal (weld_at_vulnwatch.org)
Date: 02/21/05

  • Next message: Denis Jedig: "Re: SHA-1 broken"
    Date: Mon, 21 Feb 2005 15:42:08 -0500 (EST)
    To: Jay Calvert <jcalvert@habaneronetworks.com>
    
    

    On Sat, 19 Feb 2005, Jay Calvert wrote:

    >
    >
    > By adding a new key to the registry in
    > HKEY_LOCAL_MACHINE/SYSTEM/Services/SharedAccess/Parameters/FirewallPolicy/StandardProfile/AuthorizedApplications/List
    > you can circumvent the whole purpose of the firewall with out the users
    > interaction or knowledge. Spyware / Adware manufacturer's are already
    > do this.

    This is not a backdoor or vulnerability. The default permissions on this
    key are Full Control for SYSTEM and Administrators and Read for Users.
    The Administrator should be able to configure the firewall to allow
    programs to connect outbound.

    The security problem that has created the spyware malaise on Windows is
    the default Windows installation for home users, which creates the user's
    named account in the Administrators group. When this account is used to
    browse the internet there is no protection to prevent spyware/malware from
    bypassing security mechanisms, such as the XP SP2 firewall, by exploiting
    vulnerabilities or tricking the user.

    The advent of spyware/malware using NT rootkit technology to hide from AV
    and Anti-spyware programs will force Microsoft to change to an
    installation where there are 2 accounts, one for administration and a
    low permission one for browsing the internet. This has been the standard
    for Linux and OS X for years.

    -Chris


  • Next message: Denis Jedig: "Re: SHA-1 broken"

    Relevant Pages

    • Re: Windows Firewall Has A Backdoor
      ... key are Full Control for SYSTEM and Administrators and Read for Users. ... The Administrator should be able to configure the firewall to allow ... The security problem that has created the spyware malaise on Windows is ... named account in the Administrators group. ...
      (VulnWatch)
    • Re: Major Security Problems, Fradulent use on accounts! HELP
      ... I dont think its spyware ... | Norton Firewall for over a year but itslowed my computer right down. ... If you are connected to Broadband Internet the I suggest obtaining a Cable/DSL Router such ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Major Security Problems, Fradulent use on accounts! HELP
      ... > | Ive recently had someone log into my paypal account and try to ... > dont think its spyware ... > | Norton Firewall for over a year but itslowed my computer right down. ... > Cable/DSL Router such ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Help on SEARCH with MSN
      ... It is not spyware or any of those as I have them all ... You should periodically defragment your hard drives as well as check them ... using Windows XP "prettifications". ... You should at least turn on the built in firewall. ...
      (microsoft.public.windowsxp.configuration_manage)
    • Re: Spyware problems
      ... > spyware, and a link to a removal site. ... Depends on what "no matter what I do" includes... ... using Windows XP "prettifications". ... You should at least turn on the built in firewall. ...
      (microsoft.public.security)