Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

AutoRun on Windows: The end of this functionality is approaching (I)

Microsoft has just released as an automatic update the patch that disables Autoplay on USB devices on all its Windows (only version 7 did it correctly by default until now). With this move, he takes (finally) the final step to annihilate a functionality that has brought many problems. Let's review a little the history of the Autorun.

Although Windows 9x had AutoRun, it was a kind of primitive system that could not be compared to XP. In addition, at that time USB storage devices were not too popular, while floppy disks were still used. Therefore, it can be said that the real problem began at the end of 2001, with XP and its Autorun and Autoplay. Let's distinguish between these two concepts.

Autorun and Autoplay

Autorun: It is the ability of the operating system (not only Windows) to run removable devices when they are inserted into the system. In Windows, the parameters of "autorun" are defined in a text file called autorun.inf, which appears in the root of the drive being inserted.

Autoplay: It is the own functionality introduced in XP. It complements and is based on Autorun. It analyzes the device that is inserted and depending on the type of file it finds, launches a dialogue in which the best applications to play them are suggested. If a default action is chosen, the user will no longer need this dialog and the chosen program will be launched automatically next time thanks to Autorun and the Autoplay "memory".

- Publicidad -

Important milestones

Already in February 2000, we published in Hispasec a bulletin entitled "Attacks through the autorun". The functionality was presented as the perfect substitute for automatic execution on floppy disks but applied to CDs and USB sticks.

By 2005, USB sticks became popular and more and more malware samples began to appear that spread by this means. To the point that, in mid-2010, it was already estimated that 25% of malware was spread through these devices.

But Microsoft didn't see the problem until 2008. This capability could be disabled through policies or changes in manuals in the registry and, therefore, did not consider it necessary to change its posture: Windows offered it as active functionality by default (like so many other facilities) and who wanted to protect themselves, to deactivate it. But this was not entirely true: even deactivated, it was never truly protected. From there begins a journey for its deactivation and improvement that, to locks and ravines, is already automatically applied to all its operating systems

More Information:
How to disable autorun functionality in Windows
http://support.microsoft.com/kb/967715
02/08/2010 Microsoft releases out-of-cycle update for
vulnerability in .lnk
03/05/2009 Microsoft improves the "self-execution" of Windows 7. Thank you
Conficker?
http://www.hispasec.com/unaaldia/3844
19/02/2000 Attacks through the autorun
http://www.hispasec.com/unaaldia/480
27/05/2008 Virus and promiscuity. From floppy disk to USB
http://www.hispasec.com/unaaldia/3503
25% of malware spread via USB drives
http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=227100125

Author: Sergio de los Santos
Source: Hispasec

See original.

No thoughts on “AutoRun on Windows: The end of this functionality is approaching (I)”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Suscribase Gratis
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS

Webinar: NxWitness el VMS rápido fácil y ultra ligero

Webinar: Por qué elegir productos con certificaciones de calidad

Por: Eduardo Cortés Coronado, Representante Comercial - SECO-LARM USA INC La importancia de utilizar productos certificados por varias normas internacionales como UL , Ul294, CE , Rosh , Noms, hacen a tus instalciones mas seguras y confiables además de ser un herramienta más de venta que garantice nuestro trabajo, conociendo qué es lo que certifica cada norma para así dormir tranquilos sabiendo que van a durar muchos años con muy bajo mantenimiento. https://www.ventasdeseguridad.com/2...

Webinar: Anviz ONE - Solución integral para pymes

Por: Rogelio Stelzer, Gerente comercial LATAM - Anviz Presentación de la nueva plataforma Anviz ONE, en donde se integran todas nuestras soluciones de control de acceso y asistencia, video seguridad, cerraduras inteligentes y otros sensores. En Anviz ONE el usuario podrá personalizar las opciones según su necesidad, de forma sencilla y desde cualquier sitio que tenga internet. https://www.ventasdeseguridad.com/2...

Webinar: Aplicaciones del IoT y digitalización en la industria logística

Se presentarán los siguientes temas: • Aplicaciones del IoT y digitalización en la industria logística. • Claves para decidir el socio en telecomunicaciones. • La última milla. • Nuevas estrategias de logística y seguimiento de activos sostenibles https://www.ventasdeseguridad.com/2...

Sesión 5: Milestone, Plataforma Abierta que Potencializa sus Instalaciones Manteniéndolas Protegidas

Genaro Sanchez, Channel Business Manager - MILESTONE https://www.ventasdeseguridad.com/2...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter