<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aaron Parker &#187; Security</title>
	<atom:link href="http://blog.stealthpuppy.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.stealthpuppy.com</link>
	<description>on application delivery with application virtualization, server-based computing, desktop virtualization and more</description>
	<lastBuildDate>Thu, 05 Jan 2012 16:09:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft issues update to fix disabling Autorun</title>
		<link>http://blog.stealthpuppy.com/security/microsoft-issues-update-to-fix-disabling-autorun/</link>
		<comments>http://blog.stealthpuppy.com/security/microsoft-issues-update-to-fix-disabling-autorun/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 08:30:36 +0000</pubDate>
		<dc:creator>Aaron Parker</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Autorun]]></category>

		<guid isPermaLink="false">http://blog.stealthpuppy.com/?p=936</guid>
		<description><![CDATA[Microsoft has issued an security advisory for a non-security update (I know, sounds odd, but bear with me) - Microsoft Security Advisory (967940), Update for Windows Autorun. Specifically this update fixes an issue that prevents the NoDriveTypeAutoRun registry key from functioning as expected. &#8230; <a href="http://blog.stealthpuppy.com/security/microsoft-issues-update-to-fix-disabling-autorun/">Continue reading <span class="meta-nav">&#8594;</span></a><p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/security/microsoft-issues-update-to-fix-disabling-autorun/">Microsoft issues update to fix disabling Autorun</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-939" style="margin-left: 0px; margin-right: 10px;" title="Autorun icon (kinda)" src="http://blog.stealthpuppy.com/wp-content/uploads/2009/02/autorun.png" alt="Autorun icon (kinda)" width="100" height="100" />Microsoft has issued an security advisory for a non-security update (I know, sounds odd, but bear with me) - <a href="http://www.microsoft.com/technet/security/advisory/967940.mspx">Microsoft Security Advisory (967940), Update for Windows Autorun</a>. Specifically this update fixes an issue that prevents the <a href="http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/93502.mspx?mfr=true">NoDriveTypeAutoRun</a> registry key from functioning as expected.</p>
<p>IT World <a href="http://www.itworld.com/windows/63219/after-cert-warning-microsoft-delivers-autorun-fix">has covered the update</a> and US-CERT actually issued a security alert about the issue last month &#8211; <a href="http://www.us-cert.gov/cas/techalerts/TA09-020A.html">Microsoft Windows Does Not Disable AutoRun Properly</a>. The US-CERT article has guidance on disabling <code>AUTORUN.INF</code> completely via the IniFileMapping feature &#8211; something that <a href="http://nick.brown.free.fr/blog/2007/10/memory-stick-worms.html">Nick Brown covered back in 2007</a>.</p>
<p>There are actually two knowlegebase articles that cover the issue and the update: <a href="http://support.microsoft.com/kb/967715">How to correct &#8220;disable Autorun registry key&#8221; enforcement in Windows (967715)</a> and <a href="http://support.microsoft.com/kb/953252">How to correct &#8220;disable Autorun registry key&#8221; enforcement in Windows (953252)</a>. You&#8217;ll only need to read the first.</p>
<p>On Windows XP/2003 the update does two things &#8211; updates SHELL32.DLL and creates the registry value: <code>HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer HonorAutorunSetting</code>. You can download the updates here:</p>
<ul>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=CC4FB38C-579B-40F7-89C4-1721D7B8DAA5">Update for Windows XP (KB950582)</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=E8507286-CDF8-4BCB-AFC5-9734FE772C53">Update for Windows Server 2003 x64 Edition (KB950582)</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=705305E5-7060-4236-B5D2-40CA63A967FB">Update for Windows Server 2003 (KB950582)</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=21A0124C-6F50-4281-923E-E2B28068147A">Update for Windows XP x64 Edition (KB950582)</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=5795F63E-1FD9-4A13-9650-1015E14B6D11">Update for Windows Server 2003 for Itanium-based Systems (KB950582)</a></li>
<li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=C192EDCF-CA3D-44E3-8ECC-49C5F4DA5405">Update for Windows 2000 (KB950582)</a></li>
</ul>
<p>For Windows Vista and Windows Server 2008, this issue was addressed in Microsoft <a href="http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx">Security Bulletin MS08-038</a>, released July last year. You&#8217;ve deployed that update right?</p>
<p>So the question is then, does Autorun have a place in corporate environments? I think the answer is no &#8211; a little tradeoff in usability for a big gain in security. Here&#8217;s a few interesting articles by Steve Riley and Jesper Johasson on the subject:</p>
<ul>
<li><a href="http://blogs.technet.com/steriley/archive/2007/09/22/autorun-good-for-you.aspx">Autorun: good for you?</a></li>
<li><a href="http://blogs.technet.com/steriley/archive/2007/10/30/more-on-autorun.aspx">More on Autorun</a></li>
<li><a href="http://technet.microsoft.com/en-us/magazine/2008.01.securitywatch.aspx">Security Watch: Island Hopping &#8211; The Infectious Allure of Vendor Swag</a></li>
</ul>
<p>If we only learn two things from Conficker, they should be patch early and disable Autorun. If you&#8217;re not on top of this, you could potentially leave yourself open for a world of hurt.</p>
<p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/security/microsoft-issues-update-to-fix-disabling-autorun/">Microsoft issues update to fix disabling Autorun</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.stealthpuppy.com/security/microsoft-issues-update-to-fix-disabling-autorun/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

