Oops. Windows Autorun is fixed, almost...
You are not logged in. Access is limited. Login or see membership information. • Streetwise Security Zone Community

The Streetwise Security Zone Discussion Forums are a great way to see what other managers are doing about security and what problems they have faced. You can find a lot of helpful hints and tips that could save you time and money.

You must join The Streetwise Security Zone (click HERE) in order to reply or post new items in the forums.

Author Message

ScottWright
Group Administrator

Subject: Oops. Windows Autorun is fixed, almost...
Technical IT Security Discussions
posted by ScottWright on Saturday, March 28th 2009 @ 12:54 AM

Due to a well-known bug in Windows, for years, it's been possible to have drives with autorun.inf files in them automatically run a specified program on the drive as soon as it was connected, even if the registry settings were set correctly.

This has become a big problem for USB drives, especially since exploits like the Conficker worm started taking advantage of the broken registry settings.

Microsoft has now come out and provided a fix to the problem, so you can actually disable autorun. However, after listening to Steve Gibson's description of what you have to do to make it stick, the feature may as well still be considered broken for many versions of Windows. It is such a convoluted process to actually get the settings right, that it's very likely that people may mistakenly think they've disabled autorun when all is said and done.

They actually added a new registry setting that essentially says, "Yes, I really want to disable autorun" because they felt that making the settings work the way they originally had intended might cause many environments that depend on it running incorrectly to fail if they fixed it. Makes perfect sense, doesn't it?

You can learn all the gory details from the Security Now podcast (Episode 187), or just view the transcripts. Both are available at:

http://www.grc.com/securitynow.htm

Just look for the box with Episode 187 to find the audio program or the text transcripts. Thanks to Steve for painstakingly researching and testing the configurations. It really is an important thing to get right in order to cut down some of the risk of getting infected by Conficker.

________________________________
Scott Wright
The Streetwise Security Coach

Would your organization be interested in obtaining the right to use my lessons or articles in your enterprise security awareness program? Please email me at the address below...

Email: scott@streetwise-security-zone.com
Twitter: http://www.twitter.com/streetsec
Phone: 613-693-0997
Podcast: http://www.streetwise-security-zone.com/podcast.html

DavidB
Personal

Subject: RE: Oops. Windows Autorun is fixed, almost...
Technical IT Security Discussions
posted by DavidB on Monday, June 13th 2011 @ 4:40 PM

the latest updaate from Microsoft is here.

http://support.microsoft.com/kb/967715

The main problem I have with it is that it's a lot of techie stuff for the average user to follow = unlikely to happen.