So, I got bit again by a radio station not monitoring their web site and getting a trojan downloader. Windows Security essentials caught it and I’m pretty sure it didn’t do any damage, but I did a System Restore just in case.
It’s only been in the MSE signature file for a couple weeks, and using other tools I have, it’s clear it wasn’t written by a script kiddie. I would guess with 99% certainty this is a “State Sponsored” trojan.
Poking around, I think it may be using a clever technique to reinfect a computer even after a system restore. Internet Explorer has a very dangerous option to “Recover Tabs if IE crashes” – since a virus or trojan often causes a crash, the last thing you want to do is auto reload the pages in the browser. I suspect it is trying to trick IE into autorecovering from a crash when no crash occurred. Not sure, and that’s not the point.
So I kicked myself and said “OK, that’s IT. At least part of the problem is that I run Windows XP as the Administrator. Forgetting that I went down this path once before, I decided to do it again and hit my head again.
Windows XP out of the box has an administrator account called “Administrator” that has no password. I’ve been using XP ever since it came out (and 95 and 3.1 before that) – so everything that I have done for all that time is stored under the original Adminstrator account (with a password) – pictures, bookmarks, favorites, etc…
So, I go in to create a “Limited” account that won’t have the ability to automatically install software and make dangerous changes to the system. I really doubt that offers much protection – so much “stuff” critical to Windows is stored in the registry, and I bet there are dozens of ways to compromise a system even as a Limited User.
I go to System Settings / Users and Add a User. the first thing it announces is that this new user must be an administator account (But I already have one!). Oh well, I guess I’ll have two. So I create an administrator account and then my Limited Account. Logout so I can use the limited account – and the ACCOUNT THAT HAS EVERYTHING IN IT FOR THE LAST 3 YEARS IS GONE!
Grrr…. that’s when I remember that I did this before. The prior time – being a security conscious person, I didn’t want my adminstator account named Administrator, as it is stupid for an Operating System to use the same username for the Super user on every computer. (Is your super user on Linux still named “root”?) It’s much harder for a bad guy to break in as the Super User if they don’t know the username of your super user.
The Out of the Box Admin user is intended as basically a placeholder until you create the real administrative user (which maybe 1% of XP users even know about). Once you create your “real” admin user, Windows hides the default Admin user and won’t let you login using it any more – except in Safe Mode).
After poking around a bit, it turns out that is not 100% true – and is a HUGE security hole in Windows XP Professional. At the Welcome Screen, if you hold down Ctrl and Alt and press DEL twice, you are presented with an NT style network type login prompt. You can type in any user name there, not just those Microsoft hasn’t hidden. So if the default Administator account was never assigned a password, just typing Adminstator with no password lets you in – even if your real Administator account has a password.
The reality is that anyone with bad motives who has physical access to your computer will not have trouble getting what they want from the computer – so in the big scheme of things, it is not a huge hole. Locks are there to keep out honest people.
So now I’m just wondering if I copy or rename or move my Documents and settings from the Hidden Admin user to the visible Admin User…. just how many days will I be cleaning up this mess….
Did you hear that Apple Computers is now bigger in market cap than GM and has more cash than the federal government? I wonder why….
It isn’t greener on the Apple side of the fence, I was just thinking of bying a PC for the first time since 1994.
well, don’t know about the apple. I think I would go Unbutu First.
You know what they say: once you get Unbutu, you never go back : )
Art, I picked up a virus the other day. It was some flash/ trojan virus something. McAfee Stinger got rid of it. Running XP with Firefox.
I was blaming Yahoo finance. But I had been testing radio links that day. so it could have been either. Hate the virus, hate the Geithner.
CERT sent out an alert two(?) days ago about yet another problem with adobe flash. That’s probably what bit you.
The networks that run 3rd party ads (like Drudge) have to be very careful that they screen that the Flash doesn’t have any backdoors…. there has also been a history of people using malformed graphic images to break in. People writing code to process graphics like to assume that the incoming image doesn’t contain invalid data.
How much better is Win7 compared to XP? I’m mulling over getting a new PC – either to run the web site, or to become my new PC and use this XP machine for the web site (running Fedora).
I appreciate how Microsoft got in the position they are – back around 1995, they were late arriving at the Internet party. Their primary “customer” was the business market where servers and applications were trusted and people wanted the ability to do powerful things (like write ActiveX controls. It didn’t occur to them there are evil people in the world. So their stuff is insecure by default.
In the Linux world, there is this concept called the “chroot jail” – that even if you are running as the administrative user, the application cannot “see” outside of its own directory.
http://www.cis.syr.edu/~wedu/seed/Labs/Vulnerability/Chroot/Chroot.pdf
(I’m wondering if colleges teaching people how to exploit vulnerabilities is a good thing – there is not a lot of difference between white hats and black hats, and often people can’t see their own hat)
I’m constantly annoyed how Microsoft lets people do things to my system without my persmission – like Google Updater adding itself as a service that runs at startup… and adding scheduled tasks without asking me (cron for you linux people) When I first launched IE as my safe user, somehow Google Toolbar automatically installed itself.
Their whole model is jumbled – now that I’m using a limited user. I can turn off the screen saver from locking the system, but I can’t change the power saver settings.
I already know that “Scheduled tasks” are a problem. Because of the security holes, they can become invalidated (without warning you) and stop running.
I don’t have any concern about my computer having someone get physical access, and I’m not trying to hide anything from law enforcement. But for a business with people coming and going, this is a huge problem. I read earlier today that Mitnick apparently has a new book out describing his adventures. A lot of what he did was not so much “hacking” as it was social engineering – walking past security guards, shoulder surfing, calling people on the phone and tricking them into giving up passwords, etc….
Just as an aside – do you notice that these companies all seem to be running ads where the Customer only experiences an attempt at identity theft AFTER they sign up for the service? Ponder that for a moment.
“How much better is Win7 compared to XP?”
Oh boy! Where to begin?
On security, better. Interface options, better*.
Usability… be prepared to relearn the location of everything*. Be very cognizant of UAC caveats.
*You will most certainly want a 3rd party utility called ‘Classic Shell’ which provides the cascading menus for the Start menu (MS took that away, with no option).
Win7 is to Vista, what XP was to Win2000… an update.
That said, I installed it as a dual-boot (XP). I prefer the Aero interface features of Win7 and the fact it includes a Chess game. As a power user, I spent a fair amount of time adding ‘classic’ XP/Win2000 tools to tweak it.
Spent 3+ months learning the ropes before I converted my partner’s (an attorney) workstation over to Win7… it paid off, I had hers humming along within 24 hours.
“The reality is that anyone with bad motives who has physical access to your computer will not have trouble getting what they want from the computer…”
This is another reason why I continue to mention TrueCrypt… if you encrypt your system partition, the OS won’t even boot until you type in the correct password.
If you setup TrueCrypt this way, it appears to hang at POST, but it is just waiting for you to type in a blind password (no asterisks)… thus, unless the bad guy knows what is happening and the boot password, he’s not getting anywhere fast with it.
It has the option to create hidden partitions, offering you ‘plausible deniability’… you simply mount the volume with a password/key and it behaves like any other drive.
http://Truecrypt.org is far better than anything ‘built-in’ to Windows 7, OSX, or Linux… and it is available for all 3 major platforms (Windows, Apple, Linux).
Windows admin can certainly be frustrating at times; it has definitely brought out my ‘sailors vocabulary’ on occasion, but if you know how to research the issue you can usually recover from almost any system problem much easier than say, Linux.
To the credit of MS, I have yet to be forced to reinstall XP or Win7 to recover it… I just wish they would leave most ‘services’ turned off by default, let me decide.
For future reference, Microsoft has a partial answer to this. If you want to move your identity from the administrator user to a limited user…. go to Settings / Control Panel / System / Advanced / User Profiles / Settings and “Copy To”…. you choose the place you want your admin settings copied to – c:\documents and settings\limitedusername
That copies your startup program list and your desktop – but you’ll still have to export and import your browser cookies and favorites through a location the limited user can read. System settings in the registry are not carried forward.
If you use the Spades game in Windows (I’m addicted, I admit it)…. even though you’re on the same computer, you have to start over again building up your reputation (the game doesn’t show you your reputation, but it’s clear it does do that after playing it a long time…. if you set your skill level to expert and it keeps dropping people who are beginners in your game, that’s a strong hint you aren’t really an expert)
To elaborate further, if you’ve been reading what I’ve written over the past few months, you know that I’ve been experimenting with the various flavors of Linux if/when I decide to move the server into my own house. The first step I went down that path was creating a bootable thumb drive with a LiveCD image.
Fedora has the ability to mount a NTFS partition with read AND write capability. If you try to mount a NTFS filesystem on a normal Fedora system (not LiveCD), it demands that you enter the super user password – the root password for Linux which you control!, not the Windows Password protecting the file system. The LiveCD image has no password on root, so it doesn’t even prompt you – you just have direct access to the Windows hard drive without any security. No wonder that Wikileaks dweeb was able to download GB of data onto a thumb drive. Any Windows PC that has the ability to boot from a USB device is vulnerable. The BIOS Boot Menu that lets you change the device order in which the system tries to boot is not password protected (unless you restrict it).
The fundamental flaw in all types of security is that every security method needs a failsafe method to bypass it. If the key that operates your car is completely secure and had no backdoor, if you lost your key, you would have to take your car to the scrap yard and destroy it. So every security method needs a back door (the dealer goes into a database and finds the code for the key and makes a new one). The secure keybob is also an ordinary mechanical key. The badge system to open a door also has a mechanical lock so the boss can sneak in and out without being recorded, etc…
Now there goes an awful lot of words describing why I bought a Mac and never looked back. I’d almost forgotten what a pain in the ass MicroSoft is. Thanks for the memories.
Heading down the stupidity path, I’ll leave breadcrumbs in case I vanish….
So many (most?) programs in Windows keep their settings stored in the registry. They’re under ….\CurrentUser\ApplicationData, so depending on who is logged on, the application sees that user’s preferences…. So in order to transfer my application data settings between users, I decide that means I need to export the ApplicationData key tree to a shared space that both users can see (C:\)…. then login as my limited user and import the 23 MB of registry data under that user. That appears to have worked. Limited users can’t run Regedit – but curiously they can double click a .reg file and will gladly import the registry entries into the “hive” under the limited User profile.
Great!…. [I expect unintended consequences beyond the annoying “I now have different settings for different users]. My goal is that I won’t use administrator user at all except when I need to – like installing new software.
So I login as LimitedUser. One of the icons on my desktop is MalwareBytes. I get inspired to run a scan. It tells me my data file is 68 days old, and I should really update it. I agree. So I download it. The download fails because MalwareBytes doesn’t have write authority to a file it needs – and offers up a generic “What’s up with this?” error, and suggests I contact support. So like in the entire history of MalWareBytes, no user has ever tried to run it as a limited user? (fairly likely)
Surely Microsoft Security Essentials has thought of that. Sure enough, it works OK…. but gets me thinking – if some malware succeeds in causing damage to the system, will the malware removal software be unable to deal with it unless I’m running as Administrator (that seems very likely)
Now I can’t edit my php source files – the Backup directory is a place I don’t have write access to (the editor’s installation directory) and once I point that to a new place, I still don’t have the ability to write the file (presumably because the file is owned by Administator)
The more you’ve used a super user, the harder it is not not use the super user.
So I log back in as Administator to figure out how to let LimitedUser have access to the folder where the php source files (also the location that my Apache web server looks for there in my test environment). It offers me two options…. Move it to “Shared Folders”…. Bzzzzt! or Set up a Network Share Bzzzzt! Opening up a network share would kind of defeat the purpose that I’m trying to make my system MORE secure.
There must be a way to change the ownership of a folder and its files (chown in linux)….. so Microsoft has this explanation
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/acl_take_ownership.mspx?mfr=true
Sounds great – just right click the folder, go to Properties and click the Security Tab. Oops, there is NO Security Tab. Did it go away in some XP update? Is it somewhere else? Is it not showing because of Policy Rule that says on my machine I can’t change the owner? Am I logged in as Administrator or LimitedUser? Where can I do a whoami command?
Oh reading on, since I’m not connected to a Domain (like a business user at work, I can’t see the Security Tab unless I do something else) – I have to go to the Control Panel and change a folders setting there. It says to Go to Appearances and themes and look for Folder Options (apparently different from just Folder Options)…. and turn off “Simple File Sharing” – great, now I can have Complicated File Sharing.
Let’s see – I’ve been using computers since 1976 and had a PC since 1981… and I’m getting completely frustrated by this. Imagine how your AOL using grandmother would feel?
from my own experiences, I know if I now go to a forum where Microsoft’s vaunted MVP’s hang out, they’re give me a snotty answer calling me a dumbass and never actually providing a userful answer that doesn’t involve writing a C# script. (like IRC #Unix and perl)
The Security Tab now shows – and as promised, it is Complex. It’s now assuming that I”m in a WAN work environment with a centralized server who wants to control what LimitedUser is able to do across the entire network or which other users on the network I want to be able to use my files. I’m not on a F*king network! It does offer me a checkbox to allow anyone to do anything to the files. Okay, I’ll do that, but that kind of defeats the purpose that I don’t want user JoeHacker who manages to access my system to look around.
It seems to offer an option to let me actually change the owner of the folder to Limiteduser (which is what I want – if I do that can Apache read it?), but you have to be a Certified Microsoft Professional to even understand its question.
Select the Object Type:
Users, Groups, or Built-in security principals
It offers me an option to actually change the Onwer, but LimitedUser is not listed as someone I can give ownership to.
I notice that I can turn on Auditing so that my corporations CPA firm or internal audit firm can be notified that I’m attempting to make an unauthorized transfer of the ownership of this sensitive data.
Does it sound to you yet like I’m about willing to give up?
Postscript: Now Internet Explorer says that I don’t have permission to move a toolbar favorite into a folder on the toolbar (Using a folder on the IE Toolbar is EXTREMELY useful)
So trying to remember how I unbumped my head the first time….
from the DOS command line we have the wonderful command
control userpassswords2
Which is the blunt 50 pound sledgehammer, and I’m ready to swing. It offers up all the users on the computer, with a 1 button Remove (after a confirmation).
I kill the 2nd administrator account that I never wanted in the first place and logoff. Now that I no longer have a visible Administor account, the invisible one returns as a login choice. Mission Accomplished. Until the next problem I find.
WTF does Windows need a “Guest” account that you can’t delete that allows anyone (including other users on your local network – which might include someone who figures out a way to hack into your wireless router) to login to the computer without a password?
Since this is Microsoft Rant Day… someone needs to kick ass throughout the company over the wording of “Preferences” and “Options”.
Option:
“Don’t Prompt for Client Certificate when no Certificates or only one Certificate exists”.
o Disable
o Enable
So if I choose Disable, does that mean that I want to disable not prompting when there is no certificate? Disablling not prompting would meant that it would prompt. That’s a triple negative. Who the hell writes logic like that?
At least make the options match the question:
“Prompt for Client Certificate when no Certificates or only one Certificate exists”.
o Prompt for Client Certificate
o Ignore
That sounds like the wording for the options in Internet Explorer. What makes that situation even worse is that over time, the wording has changed to remove (or maybe to add!) some of those negatives, and that changes which of the two options should be selected.
It amazes me that they spend millions on their product development and still have atrocious wording for options like that.
Once upon a time, Microsoft zoomed out in the lead because they spent a lot of money creating a thing they called the “Usability Lab” – a room with one way mirror, TV cameras, and instrumented PCs. They would take typical users of their products, give them a task to do, and see where they got confused or made wrong choices – and then debrief them after the session to solicit opinions about the problems and ways to improve the User Interface and usability of the software. Did they just forget about that?
And really, I don’t give a rat’s ass about .NET – I still have no idea what it actually does or why I need it. Don’t stick it as the first set of options in Internet Explorer and make me scroll through all the options. The answer to everything is “NO”. I keep uninstalling it, but things keep insisting that I must have it. I don’t trust it, I don’t want it, stick it up your posterior orifice.
I’ve given up trying to use a Limited User. I’m not a child. The purpose of creating it was not to keep my 3 year old from seeing porn. I want Internet Explorer and other applications to be unable to make dangerous changes to the registry and not allow writing or modifying files in system folders without my consent. That’s it.
A “Limited user” is not allowed to update the System Time, even using the NTP sync function. My clock is now about 35 seconds different than the web site, which creates problems.