RE: Re[2]: [Full-disclosure] Next generation malware: Windows Vista's gadget API



"Roger A. Grimes" <roger@xxxxxxxxxxxxxx> writes:

I'm sorry, we'll have to agree to disagree. I don't see the new attack vector
here. I, the attacker, have to make you download my malicious trojan program,
which you install on your computer.

It's not so much the attack vector, it's the usability issue. This makes it
just too easy to convince users to download and execute untrusted content.

But if you're worried that your users will click past 3 to 5 warning messages
to install untrusted gadgets (which they will), then completely control them
using group policy.

On Joe Sixpack's PC in his den?

(As you say, I think we'll have to agree to disagree on this one. Let's wait
until the phishers discover it and then revisit the topic :-).

Peter




Relevant Pages

  • RE: Re[2]: [Full-disclosure] Next generation malware: Windows Vistas gadget API
    ... which you install on your computer. ... It's not so much the attack vector, ... just too easy to convince users to download and execute untrusted content. ... to install untrusted gadgets, ...
    (Bugtraq)
  • RE: Re[2]: [Full-disclosure] Next generation malware: Windows Vistas gadget API
    ... The lack of a defense vector doesn't translate magically to a new attack vector. ... The absence of common security mitigating controls is referred to as a vulnerability. ... just too easy to convince users to download and execute untrusted content. ... to install untrusted gadgets, ...
    (Vuln-Dev)
  • RE: Re[2]: [Full-disclosure] Next generation malware: Windows Vistas gadget API
    ... The lack of a defense vector doesn't translate magically to a new attack vector. ... The absence of common security mitigating controls is referred to as a vulnerability. ... just too easy to convince users to download and execute untrusted content. ... to install untrusted gadgets, ...
    (Bugtraq)
  • Re: WindowsUpdate_80240016 error
    ... They guy has just directed you to download malicious or crapware. ... Update will not install and shows Error Code 80240016 - computer runs forever but nothing happens. ... - but Vista will not allow me to rename the folder even tho I am an Admin ... Stop the Windows Update service ...
    (microsoft.public.windows.vista.general)
  • Re: spyware not working
    ... You cannot really "download from a disc" - you could install. ... Microsoft has these suggestions for Protecting your computer from the ... More full function applications for CD/DVD burning would be: ...
    (microsoft.public.windowsxp.security_admin)