<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows 7 UAC code-injection vulnerability: video demonstration, source code released</title>
	<atom:link href="http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/</link>
	<description>All the stuff about Microsoft and technology you haven&#039;t read anywhere else.</description>
	<lastBuildDate>Sat, 21 Nov 2009 07:05:34 +1100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: faq-o-matic.net &#187; Kompromisse zwischen Sicherheit und Bequemlichkeit? Das Beispiel UAC</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76274</link>
		<dc:creator>faq-o-matic.net &#187; Kompromisse zwischen Sicherheit und Bequemlichkeit? Das Beispiel UAC</dc:creator>
		<pubDate>Thu, 25 Jun 2009 15:06:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76274</guid>
		<description>[...] [Windows 7 UAC code-injection vulnerability: video demonstration, source code released - istartedsomething] http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstra... [...]</description>
		<content:encoded><![CDATA[<p>[...] [Windows 7 UAC code-injection vulnerability: video demonstration, source code released - istartedsomething] <a href="http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstra.." rel="nofollow">http://www.istartedsomething.com/20090613/windows-7-uac-code-injection -vulnerability-video-demonstra..</a>. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leo Davidson</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76252</link>
		<dc:creator>Leo Davidson</dc:creator>
		<pubDate>Wed, 24 Jun 2009 18:19:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76252</guid>
		<description>(Though, yes, the terminal can grab passwords, just like a spoofed UAC prompt can. Sudo works very differently to UAC, though, and to claim they are equivalent is ridiculous.)</description>
		<content:encoded><![CDATA[<p>(Though, yes, the terminal can grab passwords, just like a spoofed UAC prompt can. Sudo works very differently to UAC, though, and to claim they are equivalent is ridiculous.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leo Davidson</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76250</link>
		<dc:creator>Leo Davidson</dc:creator>
		<pubDate>Wed, 24 Jun 2009 18:16:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76250</guid>
		<description>Congratulations, STKD, on completely failing to understand how sudo works! To collect your free prize please run &quot;sudo clue&quot; on your imaginary Linux system. Have a nice day!</description>
		<content:encoded><![CDATA[<p>Congratulations, STKD, on completely failing to understand how sudo works! To collect your free prize please run &#8220;sudo clue&#8221; on your imaginary Linux system. Have a nice day!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: STKD</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76240</link>
		<dc:creator>STKD</dc:creator>
		<pubDate>Wed, 24 Jun 2009 12:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76240</guid>
		<description>Oh here we are in front of this highly secure Linux/OSX system I just found running. Let&#039;s try to run something...
Oh bugger, it needs a password I don&#039;t have. I guess that&#039;s me well and truly defe... WAIT... what if...
/types sudo passwrd in terminal
Shit i defeated their uber complex security! LINUX IS NOW VULNERABLE! OSX IS NOW VULNERABLE!
HOLY SHART DOES ANYONE KNOW ABOUT THIS?!
Now to publish a tabloid-quality article for osnews about how every Linux/OSX system is unsecure to an admin.</description>
		<content:encoded><![CDATA[<p>Oh here we are in front of this highly secure Linux/OSX system I just found running. Let&#8217;s try to run something&#8230;<br />
Oh bugger, it needs a password I don&#8217;t have. I guess that&#8217;s me well and truly defe&#8230; WAIT&#8230; what if&#8230;<br />
/types sudo passwrd in terminal<br />
Shit i defeated their uber complex security! LINUX IS NOW VULNERABLE! OSX IS NOW VULNERABLE!<br />
HOLY SHART DOES ANYONE KNOW ABOUT THIS?!<br />
Now to publish a tabloid-quality article for osnews about how every Linux/OSX system is unsecure to an admin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [Windows 7] Source Code to UAC Injection Flaw Released - TechEnclave</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76223</link>
		<dc:creator>[Windows 7] Source Code to UAC Injection Flaw Released - TechEnclave</dc:creator>
		<pubDate>Wed, 24 Jun 2009 05:13:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76223</guid>
		<description>[...] they have no interest in fixing it anyway - and Long Zheng, fellow advocate of fixing this bug, made a very clear demonstration video.  More: Source Code to UAC Injection Flaw [...]</description>
		<content:encoded><![CDATA[<p>[...] they have no interest in fixing it anyway &#8211; and Long Zheng, fellow advocate of fixing this bug, made a very clear demonstration video.  More: Source Code to UAC Injection Flaw [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76218</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Tue, 23 Jun 2009 20:48:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76218</guid>
		<description>&quot;slither of doubt&quot;?  You mean &quot;sliver of doubt&quot;.</description>
		<content:encoded><![CDATA[<p>&#8220;slither of doubt&#8221;?  You mean &#8220;sliver of doubt&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DotNetBurner - Security</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76211</link>
		<dc:creator>DotNetBurner - Security</dc:creator>
		<pubDate>Tue, 23 Jun 2009 16:32:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76211</guid>
		<description>&lt;strong&gt;Windows 7 UAC code-injection vulnerability: video demonstration, source code released  -  istartedsomething...&lt;/strong&gt;

DotNetBurner - burning hot .net content...</description>
		<content:encoded><![CDATA[<p><strong>Windows 7 UAC code-injection vulnerability: video demonstration, source code released  &#8211;  istartedsomething&#8230;</strong></p>
<p>DotNetBurner &#8211; burning hot .net content&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IT资讯速客™ &#187; Blog Archive &#187; Windows 7 UAC存在漏洞 攻击源代码公开</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76205</link>
		<dc:creator>IT资讯速客™ &#187; Blog Archive &#187; Windows 7 UAC存在漏洞 攻击源代码公开</dc:creator>
		<pubDate>Tue, 23 Jun 2009 11:47:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76205</guid>
		<description>[...] 知名Windows 7博客Long Zheng最近指出Windows 7用户账户控制（UAC）系统的默认设置存在安全漏洞，可能会导致用户被恶意软件绕过UAC进行攻击，让UAC成为虚设功能。微软对策声明说UAC并无问题，并声明无意修正此漏洞。在微软做出如上表示之后，Long Zheng目前在博客上公开了UAC注入漏洞攻击的源代码，并放出了攻击视频演示教程。 [...]</description>
		<content:encoded><![CDATA[<p>[...] 知名Windows 7博客Long Zheng最近指出Windows 7用户账户控制（UAC）系统的默认设置存在安全漏洞， 可能会导致用户被恶意软件绕过UAC进行攻击，让UAC成 虚设功能。微软对策声明说UAC并无问题，并声明无 修正此漏洞。在微软做出如上表示之后，Long Zheng目前在博客上公开了UAC注入漏洞攻击的源代码， 放出了攻击视频演示教程。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leo Davidson</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76141</link>
		<dc:creator>Leo Davidson</dc:creator>
		<pubDate>Mon, 22 Jun 2009 14:12:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76141</guid>
		<description>More food for thought from Chris Corio:

http://www.withinwindows.com/2009/06/10/uac-uac-go-away-come-again-some-other-day/comment-page-1/#comment-4025

If you keep reading after his reply, skip my &quot;7:38am&quot; reply as I had a HTML mishap. I re-posted it with corrections directly afterwards (&quot;7:52am&quot;):

http://www.withinwindows.com/2009/06/10/uac-uac-go-away-come-again-some-other-day/comment-page-1/#comment-4036

I also stumbled on this off-message post which is another example of MS doing a bad job of explaining what they&#039;re now saying UAC is supposed to be for (and not for), even internally:

http://shippingseven.blogspot.com/2008/04/okso.html

(Assuming the blog is really by someone working on Windows 7.) FWIW, I agree with what the blog says and am pointing it out because it contradicts &quot;the message&quot; and not because I think it&#039;s wrong. I agree with the blog that UAC is, or was, an imperfect but useful defence against some malware doing worse than it could, e.g. http://en.wikipedia.org/wiki/Conficker#Operation</description>
		<content:encoded><![CDATA[<p>More food for thought from Chris Corio:</p>
<p><a href="http://www.withinwindows.com/2009/06/10/uac-uac-go-away-come-again-some-other-day/comment-page-1/#comment-4025" rel="nofollow">http://www.withinwindows.com/2009/06/10/uac-uac-go-away-come-again-som e-other-day/comment-page-1/#comment-4025</a></p>
<p>If you keep reading after his reply, skip my &#8220;7:38am&#8221; reply as I had a HTML mishap. I re-posted it with corrections directly afterwards (&#8221;7:52am&#8221;):</p>
<p><a href="http://www.withinwindows.com/2009/06/10/uac-uac-go-away-come-again-some-other-day/comment-page-1/#comment-4036" rel="nofollow">http://www.withinwindows.com/2009/06/10/uac-uac-go-away-come-again-som e-other-day/comment-page-1/#comment-4036</a></p>
<p>I also stumbled on this off-message post which is another example of MS doing a bad job of explaining what they&#8217;re now saying UAC is supposed to be for (and not for), even internally:</p>
<p><a href="http://shippingseven.blogspot.com/2008/04/okso.html" rel="nofollow">http://shippingseven.blogspot.com/2008/04/okso.html</a></p>
<p>(Assuming the blog is really by someone working on Windows 7.) FWIW, I agree with what the blog says and am pointing it out because it contradicts &#8220;the message&#8221; and not because I think it&#8217;s wrong. I agree with the blog that UAC is, or was, an imperfect but useful defence against some malware doing worse than it could, e.g. <a href="http://en.wikipedia.org/wiki/Conficker#Operation" rel="nofollow">http://en.wikipedia.org/wiki/Conficker#Operation</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Windows 7 Hala Riskli</title>
		<link>http://www.istartedsomething.com/20090613/windows-7-uac-code-injection-vulnerability-video-demonstration-source-code-released/comment-page-2/#comment-76130</link>
		<dc:creator>Windows 7 Hala Riskli</dc:creator>
		<pubDate>Mon, 22 Jun 2009 10:30:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.istartedsomething.com/?p=3643#comment-76130</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
