<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MS: Be Careful With Those Function Keys</title>
	<atom:link href="http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: xAdmin</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3098</link>
		<dc:creator>xAdmin</dc:creator>
		<pubDate>Wed, 03 Mar 2010 17:22:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3098</guid>
		<description>I don&#039;t see how this is a big issue. It requires user interaction where someone has to be duped into pressing the F1 key while browsing an Internet website that has this malicious payload. I know, I know, end users do these things all the time. But, you can&#039;t protect everyone from everything 24/7. There has to be some personal responsibility/critical thinking taking place by the end user. If you&#039;re browsing an INTERNET website (not Intranet -read internal), why would you EVER press the F1 key just because the website asks you to? This is one of those issues where it comes down to the person behind the keyboard.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>I don&#8217;t see how this is a big issue. It requires user interaction where someone has to be duped into pressing the F1 key while browsing an Internet website that has this malicious payload. I know, I know, end users do these things all the time. But, you can&#8217;t protect everyone from everything 24/7. There has to be some personal responsibility/critical thinking taking place by the end user. If you&#8217;re browsing an INTERNET website (not Intranet -read internal), why would you EVER press the F1 key just because the website asks you to? This is one of those issues where it comes down to the person behind the keyboard.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3098" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3098', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3098-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3098" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3098', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3098-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JesWonderin</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3093</link>
		<dc:creator>JesWonderin</dc:creator>
		<pubDate>Wed, 03 Mar 2010 15:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3093</guid>
		<description>Hmm, so they &quot;good news&quot; is that nobody hits F1? It seems the &quot;sandbox&quot; of IE is leaking everywhere. Where I work every training course emphasises hitting F1 as it is usually context senstitive to where the user is in an application, where the &quot;Help&quot; is not. And in Access and Excel, in VBA and in macros it is the &quot;go to&quot; tool. It takes the burden off the helpdesk as well with routine questions, and as stated previously we also have modified some of the helpdesk reponses for user with company specific info. So MS, this is a biggie.</description>
		<content:encoded><![CDATA[<p>Hmm, so they &#8220;good news&#8221; is that nobody hits F1? It seems the &#8220;sandbox&#8221; of IE is leaking everywhere. Where I work every training course emphasises hitting F1 as it is usually context senstitive to where the user is in an application, where the &#8220;Help&#8221; is not. And in Access and Excel, in VBA and in macros it is the &#8220;go to&#8221; tool. It takes the burden off the helpdesk as well with routine questions, and as stated previously we also have modified some of the helpdesk reponses for user with company specific info. So MS, this is a biggie.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3093" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3093', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3093-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3093" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3093', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3093-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: SE Wireless Motion Sensor Light &#8211; 10 Super-Bright LED &#171; Best Electronics Products</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3087</link>
		<dc:creator>SE Wireless Motion Sensor Light &#8211; 10 Super-Bright LED &#171; Best Electronics Products</dc:creator>
		<pubDate>Wed, 03 Mar 2010 13:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3087</guid>
		<description>[...] MS: Be Careful With Those Function Keys — Krebs on Security [...]</description>
		<content:encoded><![CDATA[<p>[...] MS: Be Careful With Those Function Keys — Krebs on Security [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3087" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3087', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3087-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3087" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3087', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3087-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Cuidado con la tecla F1 de ayuda en Internet Explorer &#124; CyberHades</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3079</link>
		<dc:creator>Cuidado con la tecla F1 de ayuda en Internet Explorer &#124; CyberHades</dc:creator>
		<pubDate>Wed, 03 Mar 2010 02:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3079</guid>
		<description>[...] en Krebs On Security   Comparte esta [...]</description>
		<content:encoded><![CDATA[<p>[...] en Krebs On Security   Comparte esta [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3079" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3079', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3079-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3079" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3079', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3079-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: LinXs 2010-03-02 &#124; Maxim's blog</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3074</link>
		<dc:creator>LinXs 2010-03-02 &#124; Maxim's blog</dc:creator>
		<pubDate>Tue, 02 Mar 2010 22:53:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3074</guid>
		<description>[...] MS: Be Careful With Those Function Keys Pressing F1 key while browsing some sites in Internet Explorer may infect your PC [...]</description>
		<content:encoded><![CDATA[<p>[...] MS: Be Careful With Those Function Keys Pressing F1 key while browsing some sites in Internet Explorer may infect your PC [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3074" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3074', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3074-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3074" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3074', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3074-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3070</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Tue, 02 Mar 2010 21:22:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3070</guid>
		<description>&quot;clicking on the F1 key&quot;

How does one &quot;click&quot; a keyboard key? ;)

(Unless you run the On-Screen Keyboard from Accessibility features)</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>&#8220;clicking on the F1 key&#8221;</p>
<p>How does one &#8220;click&#8221; a keyboard key? <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>(Unless you run the On-Screen Keyboard from Accessibility features)</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3070" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3070', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3070-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3070" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3070', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3070-down" style="font-size:14px; color:#990033;">7</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: infosec_pro</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3067</link>
		<dc:creator>infosec_pro</dc:creator>
		<pubDate>Tue, 02 Mar 2010 18:25:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3067</guid>
		<description>loved that timeline on the isec page, wonder why it remained discovered but undisclosed so long and is now revealed?</description>
		<content:encoded><![CDATA[<p>loved that timeline on the isec page, wonder why it remained discovered but undisclosed so long and is now revealed?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3067" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3067', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3067-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3067" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3067', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3067-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3065</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Tue, 02 Mar 2010 17:58:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3065</guid>
		<description>Thank you CyberNorris;

I hate the way OEMs design these keyboards! I don&#039;t work at a desk, so my wireless keyboard is all over the place, and they put the buttons right where I reach every-time! I&#039;ve disabled most of them.</description>
		<content:encoded><![CDATA[<p>Thank you CyberNorris;</p>
<p>I hate the way OEMs design these keyboards! I don&#8217;t work at a desk, so my wireless keyboard is all over the place, and they put the buttons right where I reach every-time! I&#8217;ve disabled most of them.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3065" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3065', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3065-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3065" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3065', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3065-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: CyberNorris</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3064</link>
		<dc:creator>CyberNorris</dc:creator>
		<pubDate>Tue, 02 Mar 2010 17:06:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3064</guid>
		<description>I&#039;m with JCitizen... trying to think of the last time I purposely hit F1. I probably hit it a few times a week by accident.</description>
		<content:encoded><![CDATA[<p>I&#8217;m with JCitizen&#8230; trying to think of the last time I purposely hit F1. I probably hit it a few times a week by accident.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3064" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3064', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3064-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3064" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3064', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3064-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: xAdmin</title>
		<link>http://krebsonsecurity.com/2010/03/ms-be-careful-with-those-function-keys/comment-page-1/#comment-3063</link>
		<dc:creator>xAdmin</dc:creator>
		<pubDate>Tue, 02 Mar 2010 16:54:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1414#comment-3063</guid>
		<description>Heh, the &quot;any&quot; key. Good one. I&#039;ve taken many a support call in the past where the user asked, &quot;Where is the &quot;any&quot; key?&quot; Seriously! And it&#039;s these types of users who will, like lemmings, be easily fooled into pressing the F1 key while browsing the web. Seriously, if you&#039;re that gullible there&#039;s nothing anyone can do for you.

Now if you&#039;re follwing best practice and using a defense in depth strategy which includes running as a n0n-admin (limited user), and you fall for this trick, the damage to your system will be limited to the logged in user and not compromise the entire system. Thus the reason it&#039;s one part of a layered defense. Anyway, I&#039;m preaching to the choir.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>Heh, the &#8220;any&#8221; key. Good one. I&#8217;ve taken many a support call in the past where the user asked, &#8220;Where is the &#8220;any&#8221; key?&#8221; Seriously! And it&#8217;s these types of users who will, like lemmings, be easily fooled into pressing the F1 key while browsing the web. Seriously, if you&#8217;re that gullible there&#8217;s nothing anyone can do for you.</p>
<p>Now if you&#8217;re follwing best practice and using a defense in depth strategy which includes running as a n0n-admin (limited user), and you fall for this trick, the damage to your system will be limited to the logged in user and not compromise the entire system. Thus the reason it&#8217;s one part of a layered defense. Anyway, I&#8217;m preaching to the choir.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3063" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3063', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3063-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3063" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3063', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3063-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 2/17 queries in 0.011 seconds using memcached
Object Caching 964/970 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 23:46:23 -->
