ANTICHAT.XYZ    VIDEO.ANTICHAT.XYZ    НОВЫЕ СООБЩЕНИЯ    ФОРУМ  
Баннер 1   Баннер 2
Antichat снова доступен.
Форум Antichat (Античат) возвращается и снова открыт для пользователей. Здесь обсуждаются безопасность, программирование, технологии и многое другое. Сообщество снова собирается вместе.
Новый адрес: forum.antichat.xyz
Вернуться   Форум АНТИЧАТ > Оффтоп > Forum for discussion of ANTICHAT
   
Ответ
 
Опции темы Поиск в этой теме Опции просмотра

Vista pranks possible via voice commands
  #1  
Старый 05.02.2007, 10:37
Аватар для Dracula4ever
Dracula4ever
Постоянный
Регистрация: 08.05.2006
Сообщений: 559
Провел на форуме:
1593567

Репутация: 354


Отправить сообщение для Dracula4ever с помощью ICQ Отправить сообщение для Dracula4ever с помощью AIM Отправить сообщение для Dracula4ever с помощью Yahoo
По умолчанию Vista pranks possible via voice commands

"PC, root thyself."

It may not be that easy, but users of Windows Vista may have to watch out for malicious audio files.

Prompted by a posting on a security mailing list, security experts investigated and confirmed that a computer running Microsoft's latest operating system, Windows Vista, could have system commands activated by audio files running on a Web site. While Microsoft implementation of least privilege settings for users mean that most harmful commands would have to somehow bypass Vista's User Account Control, basic commands could still delete documents on a user's PC without requiring a password, according to ZDNet information-technology blogger George Ou.

"I tested this scenario and it works," Ou wrote on the DailyDave security mailing list. "Yes you need to actually catch the user off-guard and they would have had to turn on speech recognition at some point which then autoloads speech in Vista from that point on. This does not require user interaction other than clicking on a URL to visit a website and this does not trigger UAC security warnings."

Other security experts and Microsoft have both confirmed the issue. Microsoft noted that the vulnerability has significant pre-conditions before anyone could exploit the issue.

"In order for an attack to be successful, the user would have to have a microphone and speakers connected to their system," the software giant stated in an advisory sent to SecurityFocus. "In addition, the user would have had to configure the speech recognition feature."

The audio trick is a--mainly humorous--misstep for Microsoft's initiative to lock down the Windows Vista operating system, which launched on Monday. For the most part, security researchers have given the operating system high marks for its improved security. However, the software giant has still not fixed a reported flaw in the operating system found in December.

Microsoft stressed that User Access Control, a feature of Windows Vista that requires a user to enter a password to do many administrative tasks, severely limits any threat from voice commands.



securityfocus.com
 
Ответить с цитированием

  #2  
Старый 06.02.2007, 11:52
Аватар для Sn@k3
Sn@k3
Познавший АНТИЧАТ
Регистрация: 13.04.2006
Сообщений: 1,738
Провел на форуме:
5151669

Репутация: 1198


Отправить сообщение для Sn@k3 с помощью ICQ
По умолчанию

this news was already in russian zone-)
 
Ответить с цитированием
Ответ



Похожие темы
Тема Автор Раздел Ответов Последнее сообщение
Windows Vista FAQ ~!DoK_tOR!~ Windows 4 30.11.2007 00:06
вся история Windows Vista BlackCats Чужие Статьи 6 06.02.2007 11:40
Охотники за мифами Windows Vista ~Real F@ck!~ Чужие Статьи 2 07.11.2006 10:58
Windows Vista - "Новые возможности" от Microsoft Hitman_2 Мировые новости 0 28.03.2006 01:31



Здесь присутствуют: 1 (пользователей: 0 , гостей: 1)
 


Быстрый переход




ANTICHAT.XYZ