5 ms·
A glimpse inside CryptoWall 3.0
- netheril96 11y ago> Deactivating: Shadow Copies Startup repair Windows error recovery > And stopping: Windows Security Center Service Windows Defender Windows Update Service Windows Error Reporting Service and BITS Won't these actions require administrator privileges? How do the program escalate its privilege if it starts by user clicking on a js file?
- eugenekolo2 11y agoMany people have UAC disabled.
- ploxiln 11y agoUAC gave Windows Vista a bad reputation for annoying prompts all the time, so in the interest of user experience and convenience, starting with Windows 7 Microsoft intentionally made it much less bulletproof: any Microsoft signed executable can bypass UAC. This includes common system executables which can be caused to load arbitrary dlls, this includes the control panel to turn off UAC entirely. It hasn't and won't be "fixed", it's just how it all works. http://www.pretentiousname.com/misc/win7_uac_whitelist2.html http://www.pretentiousname.com/misc/win7_uac_whitelist2.html
- noinsight 11y ago> any Microsoft signed executable can bypass UAC. If UAC is set to Medium (the default). If you're serious about security you should set it to High.
- Karunamon 11y agoUnfortunately this results in constant annoying prompts. I don't know what OSX does, but it seems like I'm prompted to escalate far less often than I would be on a high UAC system. How do the requirements compare?
- eugenekolo2 11y agoYour usage of OSX must be different than mine, because I get prompted far more than I'd like.
- politician 11y agoI wonder whether various browser vendors are investigating ways to disable loading Wordpress sites given their propensity to being taken over by exploits. The browser vendors collectively disabled/stunted Flash, maybe it's time for Wordpress to go down?
- Karunamon 11y agoIs Wordpress really that insecure, or is it the fact that it's the single most popular blogging platform out there, requires very minimal technical competence to set up, and therefore its users are doing dumb things with the configuration?
- eugenekolo2 11y agoI'd call it a combination of it being extremely popular (attackers want it), minimal technical competence, PHP, and a history of really bad bugs.
- spoiler 11y agoWordPress in itself isn't that unsafe; they are pretty diligent in fixing bugs and security issues. However that is not true about plugins, themes, various theme/plugin frameworks developed for WordPress[1], or custom-tailored things[2]. Also, we must factor in the end-users lack of technical competence[3]. Source: I work for a hosting company with lots of WordPress sites. [1]: In my experience, there's lot of purposely back-doored, or easily exploitable themes and plugins. Also, let's not forget that users and/or developers often get these illegally (without even knowing they did it; it happened a few times). [2]: The entry barrier for PHP/WordPress is extremely low and many of these developers are beginners and lack even basic understanding of security or even how things work; they base stuff off from an overly-simplified tutorial written by someone only slightly more experienced than they are. There are also inherent language and CMS issues here, but I won't go into those. [3]: We actually have users who don't to update WordPress or any of the plugins for ages. AGES! The other day, I had to argue with a client why having a WordPress version from 2006 (something from the 2.0.x release series) is a bad idea. This is either because the developer stopped supporting and abandoned development of some component their site depends on, or because of legacy custom-tailored code that was a once-off purchase.