{"id":37054,"date":"2009-11-05T16:08:26","date_gmt":"2009-11-05T21:08:26","guid":{"rendered":"tag:betanews.com,2007:article-1257455306"},"modified":"2009-11-05T16:08:26","modified_gmt":"2009-11-05T21:08:26","slug":"sophos-study-suggests-windows-7-uacs-default-setting-is-self-defeating","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/37054","title":{"rendered":"Sophos study suggests Windows 7 UAC&#8217;s default setting is self-defeating"},"content":{"rendered":"<p>By <a href=\"http:\/\/www.betanews.com\/author\/smfulton3\">Scott M. Fulton, III<\/a>, <a href=\"http:\/\/www.betanews.com\">Betanews<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" align=\"right\" class=\"img_right\" title=\"User Account Control (UAC) top story badge\" alt=\"User Account Control (UAC) top story badge\" height=\"120\" width=\"190\" src=\"http:\/\/images.betanews.com\/media\/2692.jpg\" \/><a href=\"http:\/\/www.sophos.com\/blogs\/chetw\/g\/2009\/11\/03\/windows-7-vulnerable-8-10-viruses\/\" >A blog post Tuesday<\/a> by Sophos senior security engineer Chester Wisniewski stated that recent Sophos tests revealed that User Account Control &#8212; the part of Windows that prompts the user for permission before granting elevated privileges &#8212; was ineffective in stopping common samples of malware from running, in a Windows 7-based system without virus protection.<\/p>\n<p>Whereas two of the ten chosen malware samples for the test would not run in Win7 without UAC turned on at all, only one more sample (a low-prevalence worm code-named <b>W32\/Autorun-ATK<\/b>) was thwarted by UAC. The other seven ran as though they were being blocked only by a stack of dominoes.<\/p>\n<p>Those items that ran unimpeded were: <b>Troj\/FakeAV-AFY<\/b> and <b>Troj\/FakeAV-AFX<\/b>, two low-prevalence Trojans that pretend to be a free anti-virus test; <b>Mal\/EncPk-KY<\/b> and <b>Mal\/EncPk-KP<\/b>, two garden-variety spam viruses; <b>Troj\/Agent-LIW<\/b>, a low-prevalence Trojan that adjusts the behavior of Internet Explorer; <b>Troj\/Zbot-JN<\/b>, a variation of the Trojan that attempts to steal online banking login information by first masquerading as an anonymous e-mail request for a date; and <b>W32\/Autorun-ATC<\/b>, a garden-variety worm that changes the startup script.<\/p>\n<p>&#8220;User Account Control did block one sample; however, its failure to block anything else just reinforces my warning prior to the Windows 7 launch that UAC&#8217;s default configuration is not effective at protecting a PC from modern malware,&#8221; Wisniewski wrote.<\/p>\n<p>That default configuration is a new setting for Windows 7, that&#8217;s one level down (and one level less annoying for some users) than Vista&#8217;s default. During the testing process earlier this year, <a href=\"http:\/\/www.betanews.com\/article\/Microsoft-on-Win7-UAC-Take-the-emotions-out-of-the-discussion\/1233868551\" title=\"Microsoft on Win7 UAC: 'Take the emotions out of the discussion'\">Windows 7 generated considerable controversy<\/a> for effectively enabling some applications to generate a kind of &#8220;privilege self-elevation privilege&#8221; for themselves, which some saw as a vulnerability gift-wrapped for anyone wanting to go exploiting it. Others complained about a more sweeping potential problem: that the whole point of generating the message in the first place (stopping privilege elevation) is forfeited if developers leave a back door wide open.<\/p>\n<p>As Wisniewski told Betanews this afternoon, his intention was not to prove UAC pointless in and of itself, but to suggest that Windows 7 may be vulnerable right out of the box unless and until users do something above and beyond the default.<\/p>\n<p>&#8220;This was a quick test to determine if the efficacy of restricting administrative rights through the use of UAC alone will protect against malware infecting a computer running Windows 7,&#8221; Wisniewski told us. &#8220;I did not test how it would have behaved if UAC was dialed up, or perhaps run in what people are calling &#8216;Vista mode.'&#8221;<\/p>\n<p>But if anti-virus is the solution to the problem (of course, Sophos is an anti-virus software maker), then what good is UAC at all, even if it&#8217;s dialed up? Is Chet suggesting the whole thing is pointless anyway?<\/p>\n<p>&#8220;I am performing some follow-up testing, although as is the case with malicious software, it does take a bit of time to safely perform these tests. With the data I have at the moment, I am not making recommendations as to what you do with UAC,&#8221; he responded, &#8220;merely warning people that it does not protect a machine effectively against malware. I think Microsoft acknowledges this with their efforts on Microsoft Security Essentials and Forefront.&#8221;<br \/>\nBut isn&#8217;t UAC generally effective against malicious applications that seek elevated privilege levels, even if they&#8217;re not among the most dangerous viruses cited by Sophos?<\/p>\n<p>&#8220;We did not select specific malicious or difficult samples, merely the most recent ten at the time. Most were &#8216;Fake AV&#8217; even if the sample names did not indicate that. We have generic detection for malicious packers and other nastiness that proactively finds many samples&#8230;With proper anti-malware protection, Windows 7 is far safer,&#8221; acknowledged Sophos&#8217; security engineer.<\/p>\n<p>&#8220;One benefit that UAC could have provided,&#8221; he continued, &#8220;is an additional layer of protection that would help in the event that your anti-virus has failed to detect a new sample. It does not appear from my results that this is the case.&#8221;<\/p>\n<p><a href=\"http:\/\/www.betanews.com\">Copyright Betanews, Inc. 2009<\/a><br clear=\"both\" style=\"clear: both;\"\/><br \/>\n<br clear=\"both\" style=\"clear: both;\"\/><br \/>\n  <a style='font-size: 10px; color: maroon;' href='http:\/\/www.pheedcontent.com\/hostedMorselClick.php?hfmm=v3:177b4376374e87c4687e7e984157e84f:Uxx6cKH86m0%2BQNr%2Bfk%2FEB8NHGJkl6%2FS6hqLO9%2FuSiOekLL2GAwBkA7yUW2vw8h9hW3ietUo7NYsCEw%3D%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http:\/\/images.pheedo.com\/images\/mm\/digg_64x16.png'\/><\/a><br \/>\n  <a style='font-size: 10px; color: maroon;' href='http:\/\/www.pheedcontent.com\/hostedMorselClick.php?hfmm=v3:bfc5800e89351aeb9af88bfdd610dd80:mhnez9og4YcDARRI2HH%2FxFciW%2FBnYPL0bYzZjiNBIt%2B72EPlMApGODxJ6q1vWLsAp0R4AMxtorgY'><img border='0' title='Add to Google' alt='Add to Google' src='http:\/\/images.pheedo.com\/images\/mm\/google.png'\/><\/a><br \/>\n  <a style='font-size: 10px; color: maroon;' href='http:\/\/www.pheedcontent.com\/hostedMorselClick.php?hfmm=v3:f59f5a064f217fc8a05e84d1ea71d9dc:Gj3yYnXalEH23Mb3WV2w9kL7JGpVm%2FtZEQiwPxAdfC499rcsDoovnbESwybC4b2AtAM4TQa0iUlhGQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http:\/\/images.pheedo.com\/images\/mm\/slashdot.png'\/><\/a><br \/>\n  <a style='font-size: 10px; color: maroon;' href='http:\/\/www.pheedcontent.com\/hostedMorselClick.php?hfmm=v3:49bd2acf067c506a0eebc5f954b8b621:8SYiLWkQMAEoMLWVKSQ5vuMyL1%2BkrZT1c%2BibUkVkWiXjXdMBkUMOMoBm%2Bkr%2F%2BwZab3QqN%2Bm9Ad%2FGzA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http:\/\/images.pheedo.com\/images\/mm\/twitter.png'\/><\/a><br \/>\n  <a style='font-size: 10px; color: maroon;' href='http:\/\/www.pheedcontent.com\/hostedMorselClick.php?hfmm=v3:6168286ff968a89671e661cf2f36d4cf:EoXmW3YIG1IaEGWPxZOoJGSpINtXd2C3%2BgEbbtP3usnK257C34E40L83iJIzcSuykw7gmlM%2F49t2'><img border='0' title='Add to del.icio.us' alt='Add to del.icio.us' src='http:\/\/images.pheedo.com\/images\/mm\/delicious.gif'\/><\/a><br \/>\n  <a style='font-size: 10px; color: maroon;' href='http:\/\/www.pheedcontent.com\/hostedMorselClick.php?hfmm=v3:0bc4f143cb738d88b6db482be0a406f3:zPXOl8FEgPXVDpMaTw9iLm%2Bqjoa2Oug1i3aQ7DwVQ74yEjwKLNrmNO1o6vef8nqCj5ioeFybFWZWug%3D%3D'><img border='0' title='Add to Facebook' alt='Add to Facebook' src='http:\/\/images.pheedo.com\/images\/mm\/facebook.gif'\/><\/a><br \/>\n  <a style='font-size: 10px; color: maroon;' href='http:\/\/www.pheedcontent.com\/hostedMorselClick.php?hfmm=v3:be73e8495acfedcbc7afa3471d559f05:B%2BsCJG3WBJ3D087WkTz7bqgONAgQ7PPYK%2F2staWtX1yScfCzRPaYejx0EPRM7Qvd7hNE0TUapLNwjg%3D%3D'><img border='0' title='Add to Technorati' alt='Add to Technorati' src='http:\/\/images.pheedo.com\/images\/mm\/technorati.png'\/><\/a><br \/>\n<br clear=\"both\" style=\"clear: both;\"\/><br \/>\n<a href=\"http:\/\/ads.pheedo.com\/click.phdo?s=8c1fc96010aa31d43e7a29379106ae71&#038;p=1\"><img decoding=\"async\" alt=\"\" style=\"border: 0;\" border=\"0\" src=\"http:\/\/ads.pheedo.com\/img.phdo?s=8c1fc96010aa31d43e7a29379106ae71&#038;p=1\"\/><\/a><br \/>\n<img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"0\" width=\"0\" border=\"0\" style=\"display:none\" src=\"http:\/\/a.rfihub.com\/eus.gif?eui=2225\"\/><\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.betanews.com\/~ff\/bn?a=Jmt0QUEumJA:ZB1hqQ1pN7w:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/bn?d=yIl2AUoC8zA\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.betanews.com\/~ff\/bn?a=Jmt0QUEumJA:ZB1hqQ1pN7w:V_sGLiPBpWU\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/bn?i=Jmt0QUEumJA:ZB1hqQ1pN7w:V_sGLiPBpWU\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.betanews.com\/~ff\/bn?a=Jmt0QUEumJA:ZB1hqQ1pN7w:qj6IDK7rITs\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/bn?d=qj6IDK7rITs\" border=\"0\"><\/img><\/a>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/bn\/~4\/Jmt0QUEumJA\" height=\"1\" width=\"1\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Scott M. Fulton, III, Betanews A blog post Tuesday by Sophos senior security engineer Chester Wisniewski stated that recent Sophos tests revealed that User Account Control &#8212; the part of Windows that prompts the user for permission before granting elevated privileges &#8212; was ineffective in stopping common samples of malware from running, in a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-37054","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/37054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=37054"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/37054\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=37054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=37054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=37054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}