Warning: INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'watchdog' query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:12:\"user warning\";s:8:\"%message\";s:378:\"INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'captcha_sessions'\nquery: INSERT into captcha_sessions (uid, sid, ip_address, timestamp, form_id, solution, status, attempts) VALUES (0, '67a0bdd6a2608af1dfe64c803ca27f92', '38.107.191.118', 1283517522, 'comment_form', 'undefined', 0, 0)\";s:5:\"%file\";s:87:\"/homepages/30/d251750219/htdocs/tecspeak/sites/tecspeak.com/modules/captcha/captcha.inc\";s:5:\"%line\";i:92 in /homepages/30/d251750219/htdocs/tecspeak/includes/database.mysqli.inc on line 128
Windows 7 testers found UAC security issue in beta version | Tecspeak.com
user warning: INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'captcha_sessions' query: INSERT into captcha_sessions (uid, sid, ip_address, timestamp, form_id, solution, status, attempts) VALUES (0, '67a0bdd6a2608af1dfe64c803ca27f92', '38.107.191.118', 1283517522, 'comment_form', 'undefined', 0, 0) in /homepages/30/d251750219/htdocs/tecspeak/sites/tecspeak.com/modules/captcha/captcha.inc on line 92.

Windows 7 testers found UAC security issue in beta version

Printer-friendly versionSend to friendPDF version

Microsoft went to minimize the annoyance of User Account Control in Windows 7,but some Windows 7 beta testers say they have found a serious vulnerability that could enable miscreants to turn off UAC without any user interaction.

Microsoft developer Long Zheng, author of the blog istartedsomething, on Friday posted a proof-of-concept for the vulnerability in the Windows 7 beta, and said it stemmed from Microsoft's efforts to make UAC in Windows 7 less annoying than it was when it was introduced with Windows Vista.

UAC boosts security by reducing application privileges from administrative to standard levels with a goal of minimizing the damage caused by exploits, and giving users the chance to approve or disapprove actions through pop-up dialog boxes. But many Vista users found the constant, nagging pop-up alerts UAC generated to be intolerable, and the solution, at least for some users, was simply to turn off UAC. That's why Microsoft designed a new UAC Control Panel in Windows 7 that gives administrators more control over UAC alerts.

Windows 7's default UAC setting is to alert users only when third-party programs try to make changes to a PC, and not when users make changes to Windows settings. According to Zheng, because Windows 7 considers changes to UAC as changes to Windows, no alert would be generated by turning UAC off completely, which is why this issue has dangerous implications. "You could automate a restart after UAC has been changed, add a program to the user's startup folder and because UAC is now off, run with full administrative privileges ready to wreak havoc," Zheng wrote in a blog post. The good news, according to Zheng, is that Microsoft could easily address the issue of UAC without detracting from its security benefits by forcing UAC prompt in Secure Desktop mode whenever changes are made to UAC.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <b>
  • Lines and paragraphs break automatically.
  • You may insert videos with [video:URL]

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Enter the characters shown in the image.


Warning: INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'watchdog' query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:12:\"user warning\";s:8:\"%message\";s:422:\"INSERT command denied to user &#039;dbo290624456&#039;@&#039;74.208.16.205&#039; for table &#039;accesslog&#039;\nquery: INSERT INTO accesslog (title, path, url, hostname, uid, sid, timer, timestamp) values(&#039;Windows 7 testers found UAC security issue in beta version | Tecspeak.com&#039;, &#039;node/167&#039;, &#039;&#039;, &#039;38.107.191.118&#039;, 0, &#039;67a0bdd6a2608af1dfe64c803ca27f92&#039;, 711, 1283517522)\";s:5:\"%file\";s:77:\"/homepages/30/d251750219/htdocs/tecspeak/modules/statistics/statistics. in /homepages/30/d251750219/htdocs/tecspeak/includes/database.mysqli.inc on line 128