![]() |
|
#1
|
||||
|
||||
|
Quote:
|
|
#2
|
|||
|
|||
|
Thanks for this.
__________________
Kis 2013 Emet |
|
#3
|
||||
|
||||
|
Thanks, Ron - fixed via Services and MSCONFIG.
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#4
|
||||
|
||||
|
Microsoft fix kills Windows Gadgets, warns it could lead to PC hijacks
Quote:
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#5
|
|||
|
|||
|
Quote:
Isn't this the same as the original excellent post of Ronjor?
__________________
25 forum posting etiquette tips |
|
#6
|
||||
|
||||
|
The article cites the same MS Technet findings and recommendations, otherwise, it is not.
Quote:
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#7
|
||||
|
||||
|
I made the registry changes and exported so I could distribute to other machines. I don't see them fixing this ever, since they are wanting to kill gadgets anyway.
|
|
#8
|
||||
|
||||
|
Windows 8 will not support desktop gadgets, for reason cited in this thread, that have yet to be substantiated by Microsoft as written correctly.
It has been reported in many instances the Fit-it's are inverted. ![]()
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#9
|
|||
|
|||
|
Quote:
The headings and explanations show conflicating results. |
|
#10
|
||||
|
||||
|
We are not sure, meaning, those in the security community, have implemented both, some desktop gadget functionality is removed, yet desktop gadgets can still be enabled, this is a fix that does not completely work.
I cannot say with 100 % certainty, which is which, or, what will do what. Quote:
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#11
|
||||
|
||||
|
i know some love those gadgets but imo good riddance. i dont use them nor will i ever. over the life of vista and 7 i have seen so many issues from them causing problems with various clients im personally glad to see them go.
__________________
Meatwad you're up next, with your knock-knock. Meatwad make the money see. Meatwad get the honeys G. Drivin in my car, living like a star ice on my fingers and my toes, and im a taurus "Some days your the windshield. Some days your the bug" Eset ESS V6 / Webroot WSA / Avast! IS V8 |
|
#12
|
||||
|
||||
|
I'm not using any Gadgets, so does that mean I need to do anything?
And I have no idea where to find Sidebars (I looked in Accessories), so where is it? ![]()
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#13
|
||||
|
||||
|
Please re-read further up the thread for a detailed explanation.
Quote:
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#14
|
||||
|
||||
|
I did read the thread and as a result of reading the thread I have two questions...
1. I'm not using any Gadgets, so does that mean I need to do anything? 2. I have no idea where to find Sidebars (I looked in Accessories), so where is it?
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#15
|
||||
|
||||
|
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#16
|
||||
|
||||
|
The vulnerabilities discussed in the Advisory involve the execution of arbitrary code by the Windows Sidebar when running insecure Gadgets.
Does anyone know if I still need to disable Gadgets if I am not running any of them?
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#17
|
||||
|
||||
|
The sidebar is still executed as cited here regardless of what fix-it used.
See: Code:
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#18
|
||||
|
||||
|
Quote:
I would just get rid of them altogether. Go to control panel, Programs and features, turn Windows features on or off, uncheck Windows gadget platform, reboot when prompted, done. No more gadgets. |
|
#19
|
|||
|
|||
|
Quote:
That's one of the first things I do when I install Windows 7 clean. ![]() |
|
#20
|
||||
|
||||
|
Quote:
Thanks, that was very clear! I did as you suggested. To date, I have been relying upon the description from Microsoft that states, "An attacker would have to convince a user to install and enable a vulnerable Gadget."
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#21
|
||||
|
||||
|
Quote:
![]()
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#22
|
||||
|
||||
|
Quote:
Which may be easier to have happen than one would suspect. If you for example install something like Norton Internet Security (or many other products) it installs a desktop gadget as part of the installation and opens it. An attacker would not need to prompt "Hey, install this gadget and run it too", they could slip it into many other processes. I'm sure most of the folks here would not get into that situation to begin with, but it probably wouldn't be any harder than it would be to slip a browser toolbar into your system. Better safe than sorry. |
|
#23
|
||||
|
||||
|
Quote:
Doesn't seem to me that NIS would install a vulnerable gadget on a user's system. Bottom line, though, is as you stated... better safe than sorry.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#24
|
||||
|
||||
|
Quote:
I don't expect they would, the point was ANY installer could install and run a gadget. That was just an example of how one can appear without you being specifically asked to install one. |
|
#25
|
|||
|
|||
|
Quote:
Bo |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|