funsec mailing list archives

Re: Microsoft: Vista feature designed to 'annoy users'


From: Blue Boar <BlueBoar () thievco com>
Date: Sat, 12 Apr 2008 15:49:06 -0700

Used to be that any process could send messages to almost any other. 
They went after the most egregious misuse, which was something running 
as system would show UI to the desktop user. At that point you would be 
interacting with UI running as system. The most comical cases would be 
displaying Windows help, which would let you explore and run cmd.exe as 
system, for example.

Once Vista forced the vendor to split the UI off into a process running 
as that user, that version is now "fixed" when running on XP as well.

But no, no fundamental rework of the message-passing mechanism. Maybe in 
Windows 7, where they are threatening to break compatibility with Win32.

                                        BB

Rob, grandpa of Ryan, Trevor, Devon & Hannah wrote:
Date sent:            Sat, 12 Apr 2008 12:45:43 -0700
From:                 Blue Boar <BlueBoar () thievco com>

Indeed. Vista is fixing shatter attacks for older versions of Windows, 
too. 

My understanding of Shatter was that it (partly) used the fact that any window in 
Windows could send a message (or command) to any other window.  Has this been 
changed?

======================  (quote inserted randomly by Pegasus Mailer)
rslade () vcn bc ca     slade () victoria tc ca     rslade () computercrime org
It is a chilling thought, and until the authorities come up with
a plan of action, I am urging everybody to take the sensible
precaution of developing a nervous facial tic.          - Dave Barry
http://victoria.tc.ca/techrev/rms.htm
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: