<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: UAC in Windows 7 still broken, Microsoft won&#8217;t/can&#8217;t fix code-injection vulnerability</title>
	<atom:link href="http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/</link>
	<description>All the stuff about Microsoft and technology you haven&#039;t read anywhere else.</description>
	<lastBuildDate>Sat, 21 Nov 2009 07:05:34 +1100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: GS1</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-113140</link>
		<dc:creator>GS1</dc:creator>
		<pubDate>Sat, 14 Nov 2009 07:56:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-113140</guid>
		<description>Every piece of software and every OS has vulnerabilities
If it was coded it can be exploited!

As has been said over &amp; over again. The problem is most computer users are too ill informed and ignorant.
They simply fire up their system, run no AV or Firewall and use IE.
They download and run any executable then they are shocked when they find there system has been compromised/infected.

What is needed is more education and a pro active approach,
I used to run XP everyday as Admin (With FF &amp; No/Script) and i NEVER got an infection/virus/malware/worm etc and i am not a system administrator, 
I am simply an advanced user.

But i suppose as i type this someone somewhere is trying to find exploits for Windows 7 and its only a matter of time before its unleashed and causes mayhem.</description>
		<content:encoded><![CDATA[<p>Every piece of software and every OS has vulnerabilities<br />
If it was coded it can be exploited!</p>
<p>As has been said over &amp; over again. The problem is most computer users are too ill informed and ignorant.<br />
They simply fire up their system, run no AV or Firewall and use IE.<br />
They download and run any executable then they are shocked when they find there system has been compromised/infected.</p>
<p>What is needed is more education and a pro active approach,<br />
I used to run XP everyday as Admin (With FF &amp; No/Script) and i NEVER got an infection/virus/malware/worm etc and i am not a system administrator,<br />
I am simply an advanced user.</p>
<p>But i suppose as i type this someone somewhere is trying to find exploits for Windows 7 and its only a matter of time before its unleashed and causes mayhem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: L&#8217;Antivirus gratuito di Windows 7 serve a compensare il bug nella UAC? &#124; saggiamente</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-110003</link>
		<dc:creator>L&#8217;Antivirus gratuito di Windows 7 serve a compensare il bug nella UAC? &#124; saggiamente</dc:creator>
		<pubDate>Mon, 19 Oct 2009 13:02:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-110003</guid>
		<description>[...] E su Windows? Beh, ancora deve uscire ed è già attanagliato da qualche ombra di troppo. La Gestione Account (UAC) introdotta con Vista e che ritroviamo su Seven ha un grosso bug di sicurezza, che a quanto pare la Microsoft non ha voluto o saputo risolvere. Dopo gli infiniti problemi di Windows XP in fatto di malware, Microsoft ha mutuato dai sistemi Unix-Like (come OsX o Linux) il concetto che gli utenti di base non sono Amministratori e quindi non possono compiere interventi delicati sul sistema. Su OsX infatti, quando una applicazione tenta di modificare il sistema, viene richiesta una password amministrativa per procedere. Purtroppo su Vista il risultato è stato un tedioso susseguirsi di popup, che ha sollevato non poche polemiche. Così è stato introdotto un meccanismo che permette di disabilitare, selettivamente, tali avvisi. Sin dalle primissime release di Windows 7, è stato evidenziato un Bug permette di eseguire uno script che disabilita le notifiche e permette, di fatto, di eseguire codice dannoso con privilegi di amministratore. Più volte è stato segnalato il problema dai beta tester, ma non è servito a nulla. Anche l&#8217;ultima Release Candidate presenta lo stesso bug, così come la versione che dal 22 ottobre sarà venduta sugli scaffali di tutto il mondo e nei prossimi computer. Sembra che si voglia privilegiare l&#8217;usabilità a sfavore della sicurezza (fonte UAC in Windows 7 still broken, Microsoft won’t/can’t fix code-injection vulnerability). [...]</description>
		<content:encoded><![CDATA[<p>[...] E su Windows? Beh, ancora deve uscire ed è già attanagliato da qualche ombra di troppo. La Gestione Account (UAC) introdotta con Vista e che ritroviamo su Seven ha un grosso bug di sicurezza, che a quanto pare la Microsoft non ha voluto o saputo risolvere. Dopo gli infiniti problemi di Windows XP in fatto di malware, Microsoft ha mutuato dai sistemi Unix-Like (come OsX o Linux) il concetto che gli utenti di base non sono Amministratori e quindi non possono compiere interventi delicati sul sistema. Su OsX infatti, quando una applicazione tenta di modificare il sistema, viene richiesta una password amministrativa per procedere. Purtroppo su Vista il risultato è stato un tedioso susseguirsi di popup, che ha sollevato non poche polemiche. Così è stato introdotto un meccanismo che permette di disabilitare, selettivamente, tali avvisi. Sin dalle primissime release di Windows 7, è stato evidenziato un Bug permette di eseguire uno script che disabilita le notifiche e permette, di fatto, di eseguire codice dannoso con privilegi di amministratore. Più volte è stato segnalato il problema dai beta tester, ma non è servito a nulla. Anche l&#8217;ultima Release Candidate presenta lo stesso bug, così come la versione che dal 22 ottobre sarà venduta sugli scaffali di tutto il mondo e nei prossimi computer. Sembra che si voglia privilegiare l&#8217;usabilità a sfavore della sicurezza (fonte UAC in Windows 7 still broken, Microsoft won’t/can’t fix code-injection vulnerability). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-78394</link>
		<dc:creator>Ross</dc:creator>
		<pubDate>Fri, 24 Jul 2009 02:11:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-78394</guid>
		<description>Ya Windows 7 rocks... For a word processor / email client. If you want to do any real work or gaming though, your productivity will suffer. You&#039;ll find yourself back in XP to remain competitive.</description>
		<content:encoded><![CDATA[<p>Ya Windows 7 rocks&#8230; For a word processor / email client. If you want to do any real work or gaming though, your productivity will suffer. You&#8217;ll find yourself back in XP to remain competitive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-78391</link>
		<dc:creator>Ross</dc:creator>
		<pubDate>Fri, 24 Jul 2009 02:04:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-78391</guid>
		<description>If you&#039;re not surfing around sites with questionable content, you really don&#039;t need any security at all. I&#039;ve spent the last year in XP Pro with no firewall, and no virus software and with no problems. Every once in a blue moon I&#039;d get whatever AntiVirus is most popular at the time and do a quick scan only to find that I had no malware or viruses or any other malicious software.

That being said, if someone wants to hack you, they will. They just wont be hacking you from a Microsoft Windows cocoon, most likely. Bringing Windows to a hack fight is like bringing a spoon to a gun fight.</description>
		<content:encoded><![CDATA[<p>If you&#8217;re not surfing around sites with questionable content, you really don&#8217;t need any security at all. I&#8217;ve spent the last year in XP Pro with no firewall, and no virus software and with no problems. Every once in a blue moon I&#8217;d get whatever AntiVirus is most popular at the time and do a quick scan only to find that I had no malware or viruses or any other malicious software.</p>
<p>That being said, if someone wants to hack you, they will. They just wont be hacking you from a Microsoft Windows cocoon, most likely. Bringing Windows to a hack fight is like bringing a spoon to a gun fight.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: UAC, UAC, go away, come again some other day &#124; Everything Microsoft</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-76227</link>
		<dc:creator>UAC, UAC, go away, come again some other day &#124; Everything Microsoft</dc:creator>
		<pubDate>Wed, 24 Jun 2009 06:08:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-76227</guid>
		<description>[...] was reading Mark Russinovich’s latest UAC article and Long Zheng’s latest scribblings and… developed quite the headache. Honestly, I’m tired of trying to sort out what UAC really is [...]</description>
		<content:encoded><![CDATA[<p>[...] was reading Mark Russinovich’s latest UAC article and Long Zheng’s latest scribblings and… developed quite the headache. Honestly, I’m tired of trying to sort out what UAC really is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody Real</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-76061</link>
		<dc:creator>Nobody Real</dc:creator>
		<pubDate>Fri, 19 Jun 2009 22:51:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-76061</guid>
		<description>You do realize that WriteProcessMemory and CreateRemoteThread are *NOT* non-privileged API&#039;s.  They require permissions normal users don&#039;t have.  I think it&#039;s highly deceptive to claim they&#039;re unprivileged API&#039;s when they&#039;re not.</description>
		<content:encoded><![CDATA[<p>You do realize that WriteProcessMemory and CreateRemoteThread are *NOT* non-privileged API&#8217;s.  They require permissions normal users don&#8217;t have.  I think it&#8217;s highly deceptive to claim they&#8217;re unprivileged API&#8217;s when they&#8217;re not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noticias 18-Junio-2009 - La Web de Programación</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-75992</link>
		<dc:creator>Noticias 18-Junio-2009 - La Web de Programación</dc:creator>
		<pubDate>Thu, 18 Jun 2009 21:26:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-75992</guid>
		<description>[...] Microsoft no solucionará una vulnerabilidad en el UAC de Windows 7: Aunque desconozco los motivos, la verdad es que es preocupante que exista una forma de elevar privilegios sin confirmación del UAC en W7, ya que es precisamente lo que más me gusta del Vista, el que por fin era un sistema operativo seguro (para los no entendidos, el UAC es como el sudo de Linux, ciertas acciones, carpetas y zonas del registro de Windows requieren confirmar que deseamos elevar privilegios antes de hacer nada). [...]</description>
		<content:encoded><![CDATA[<p>[...] Microsoft no solucionará una vulnerabilidad en el UAC de Windows 7: Aunque desconozco los motivos, la verdad es que es preocupante que exista una forma de elevar privilegios sin confirmación del UAC en W7, ya que es precisamente lo que más me gusta del Vista, el que por fin era un sistema operativo seguro (para los no entendidos, el UAC es como el sudo de Linux, ciertas acciones, carpetas y zonas del registro de Windows requieren confirmar que deseamos elevar privilegios antes de hacer nada). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vulnerabilidades importantes en el UAC de Windows 7 - Gratis Programas, Descarga Freeware, Warez Full, Noticias</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-75894</link>
		<dc:creator>Vulnerabilidades importantes en el UAC de Windows 7 - Gratis Programas, Descarga Freeware, Warez Full, Noticias</dc:creator>
		<pubDate>Tue, 16 Jun 2009 15:54:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-75894</guid>
		<description>[...] peor de esta vulnerabilidad es que desde el mismo blog de un fan de Windows se nos avisa de que de Microsoft podría lanzar la versión final de su sistema [...]</description>
		<content:encoded><![CDATA[<p>[...] peor de esta vulnerabilidad es que desde el mismo blog de un fan de Windows se nos avisa de que de Microsoft podría lanzar la versión final de su sistema [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vulnerabilidades importantes en el UAC de Windows 7 &#124; Malavida Blog</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-75874</link>
		<dc:creator>Vulnerabilidades importantes en el UAC de Windows 7 &#124; Malavida Blog</dc:creator>
		<pubDate>Mon, 15 Jun 2009 06:31:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-75874</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hassan</title>
		<link>http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/comment-page-2/#comment-75863</link>
		<dc:creator>Hassan</dc:creator>
		<pubDate>Sun, 14 Jun 2009 17:06:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3639#comment-75863</guid>
		<description>Windows 7 Rocks. The rest Sucks.</description>
		<content:encoded><![CDATA[<p>Windows 7 Rocks. The rest Sucks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
