<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft Warns of Uptick in Attacks on Unpatched Windows Flaw</title>
	<atom:link href="http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: drzaiusapelord</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7612</link>
		<dc:creator>drzaiusapelord</dc:creator>
		<pubDate>Mon, 19 Jul 2010 17:50:34 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7612</guid>
		<description>What? Runas is a basic functionlity of the OS since the NT days. Windows handles multiple security contexts.  Your user account is one and the admin accounts are another. Runas lets you change them. Saying Runas is a stop-gap is like saying su or sudo are stopgaps too.</description>
		<content:encoded><![CDATA[<p>What? Runas is a basic functionlity of the OS since the NT days. Windows handles multiple security contexts.  Your user account is one and the admin accounts are another. Runas lets you change them. Saying Runas is a stop-gap is like saying su or sudo are stopgaps too.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7612" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7612', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7612-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7612" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7612', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7612-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: David McCullough</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7467</link>
		<dc:creator>David McCullough</dc:creator>
		<pubDate>Sun, 11 Jul 2010 22:03:36 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7467</guid>
		<description>Great points here. I have family whose computers I regularly maintain and I believe that having them use a limited user account has saved me a lot of grief and time. 

I&#039;d prefer to see them all using 64bit Windows 7  due to its inherent protections but it&#039;s not going to happen right away so we use the defenses that we have available.

 I appreciate and have learned a lot from the informed audience here at krebsonsecurity.com.</description>
		<content:encoded><![CDATA[<p>Great points here. I have family whose computers I regularly maintain and I believe that having them use a limited user account has saved me a lot of grief and time. </p>
<p>I&#8217;d prefer to see them all using 64bit Windows 7  due to its inherent protections but it&#8217;s not going to happen right away so we use the defenses that we have available.</p>
<p> I appreciate and have learned a lot from the informed audience here at krebsonsecurity.com.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7467" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7467', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7467-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7467" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7467', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7467-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: 67GTV</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7433</link>
		<dc:creator>67GTV</dc:creator>
		<pubDate>Fri, 09 Jul 2010 18:12:03 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7433</guid>
		<description>The RunAs command is merely a stop-gap solution to, as the name implies, simply RUN an application.  ALL installations and updates should be run under the Local Administrator account.  RunAs will not give full access to the Registry among other system resources.</description>
		<content:encoded><![CDATA[<p>The RunAs command is merely a stop-gap solution to, as the name implies, simply RUN an application.  ALL installations and updates should be run under the Local Administrator account.  RunAs will not give full access to the Registry among other system resources.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7433" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7433', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7433-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7433" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7433', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7433-down" style="font-size:14px; color:#990033;">4</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: drzaiusapelord</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7429</link>
		<dc:creator>drzaiusapelord</dc:creator>
		<pubDate>Fri, 09 Jul 2010 14:44:51 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7429</guid>
		<description>Shift-right-click and select RunAs. Now just run it as admin. No need to log out.</description>
		<content:encoded><![CDATA[<p>Shift-right-click and select RunAs. Now just run it as admin. No need to log out.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7429" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7429', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7429-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7429" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7429', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7429-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Bob</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7374</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Wed, 07 Jul 2010 19:41:58 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7374</guid>
		<description>Where ever I can, I set up limited users.  If my daughter needs to install something (she&#039;s 34) she still calls dad to help her.  I have put the MS Security Essentials on all our computers (desktops, laptop, and netbook) and run limited users all the time.

Knock on wood, no problems yet.</description>
		<content:encoded><![CDATA[<p>Where ever I can, I set up limited users.  If my daughter needs to install something (she&#8217;s 34) she still calls dad to help her.  I have put the MS Security Essentials on all our computers (desktops, laptop, and netbook) and run limited users all the time.</p>
<p>Knock on wood, no problems yet.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7374" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7374', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7374-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7374" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7374', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7374-down" style="font-size:14px; color:#990033;">4</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: 67GTV</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7372</link>
		<dc:creator>67GTV</dc:creator>
		<pubDate>Wed, 07 Jul 2010 16:17:29 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7372</guid>
		<description>As Aurelius so succinctly stated, all Windows Updates and patches should be applied while logged on under the Local Administrator account.  Setting Windows Update to download and install patches automatically foregoes the hassle of this log off/log on routine on a monthly basis.

Kudos to you Bob, for running as a Limited User!  It may be an inconvenience to have to log off then back on under the Local Administrator account, but this is also inconvenient for malware execution.  Most malicious software cannot deliver the intended payload due to lack of authority under the Limited User&#039;s account.</description>
		<content:encoded><![CDATA[<p>As Aurelius so succinctly stated, all Windows Updates and patches should be applied while logged on under the Local Administrator account.  Setting Windows Update to download and install patches automatically foregoes the hassle of this log off/log on routine on a monthly basis.</p>
<p>Kudos to you Bob, for running as a Limited User!  It may be an inconvenience to have to log off then back on under the Local Administrator account, but this is also inconvenient for malware execution.  Most malicious software cannot deliver the intended payload due to lack of authority under the Limited User&#8217;s account.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7372" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7372', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7372-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7372" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7372', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7372-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Aurelius</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7365</link>
		<dc:creator>Aurelius</dc:creator>
		<pubDate>Tue, 06 Jul 2010 08:53:39 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7365</guid>
		<description>ALL updates to the system require Admin privileges. Absolutely all. The only updates that don&#039;t require Admin privileges are updates that don&#039;t actually affect the entire OS installation but just one user account. 

This vulnerability probably isn&#039;t even exploitable with a decent browser, btw. Opera for example should not process HCP urls so it shouldn&#039;t be vulnerable (unless you&#039;re using the WMP plugin, which you probably shouldn&#039;t be). See here: http://my.opera.com/community/forums/topic.dml?id=610682</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>ALL updates to the system require Admin privileges. Absolutely all. The only updates that don&#8217;t require Admin privileges are updates that don&#8217;t actually affect the entire OS installation but just one user account. </p>
<p>This vulnerability probably isn&#8217;t even exploitable with a decent browser, btw. Opera for example should not process HCP urls so it shouldn&#8217;t be vulnerable (unless you&#8217;re using the WMP plugin, which you probably shouldn&#8217;t be). See here: <a href="http://my.opera.com/community/forums/topic.dml?id=610682" rel="nofollow">http://my.opera.com/community/forums/topic.dml?id=610682</a></p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7365" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7365', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7365-up" style="font-size:14px; color:#009933;">9</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7365" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7365', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7365-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Bob</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7364</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Tue, 06 Jul 2010 05:33:42 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7364</guid>
		<description>I clicked on the link to download the Fixit routine.  It landed on my desktop.  I run as a limited user.  It won&#039;t install unless I&#039;m an admimistrator.  Why can&#039;t Microsoft (or anybody who is updating a program) tell the user what rights and permissions are required BEFORE you download the update?</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>I clicked on the link to download the Fixit routine.  It landed on my desktop.  I run as a limited user.  It won&#8217;t install unless I&#8217;m an admimistrator.  Why can&#8217;t Microsoft (or anybody who is updating a program) tell the user what rights and permissions are required BEFORE you download the update?</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7364" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7364', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7364-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7364" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7364', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7364-down" style="font-size:14px; color:#990033;">7</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: n3td3v</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7363</link>
		<dc:creator>n3td3v</dc:creator>
		<pubDate>Tue, 06 Jul 2010 00:17:57 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7363</guid>
		<description>http://n3td3v.blogspot.com/2010/07/message-from-discussion-cyber.html

Andrew</description>
		<content:encoded><![CDATA[<p>Hidden due to low comment rating. <a href="javascript:crSwitchDisplay('ckhide-7363');" title="Click to see comment">Click here to see</a>.</p><div id='ckhide-7363' style="display:none; opacity:0.6;filter:alpha(opacity=60) !important;"><p><a href="http://n3td3v.blogspot.com/2010/07/message-from-discussion-cyber.html" rel="nofollow">http://n3td3v.blogspot.com/2010/07/message-from-discussion-cyber.html</a></p>
<p>Andrew</p>
</div><div class="CommentRating">Poorly-rated. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7363" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7363', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7363-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7363" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7363', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7363-down" style="font-size:14px; color:#990033;">15</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: David Chasey</title>
		<link>http://krebsonsecurity.com/2010/07/microsoft-warns-of-uptick-in-attacks-on-unpatched-windows-flaw/comment-page-1/#comment-7362</link>
		<dc:creator>David Chasey</dc:creator>
		<pubDate>Mon, 05 Jul 2010 21:03:45 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3904#comment-7362</guid>
		<description>My assumption has been that it&#039;s better  to be free of a third party website, such as The Washington Post and The New York Times. - David</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>My assumption has been that it&#8217;s better  to be free of a third party website, such as The Washington Post and The New York Times. &#8211; David</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7362" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7362', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7362-up" style="font-size:14px; color:#009933;">7</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7362" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7362', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7362-down" style="font-size:14px; color:#990033;">6</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 8/21 queries in 0.009 seconds using memcached
Object Caching 960/974 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-12 06:50:19 -->
