Поделиться через


Comments on US-CERTs Advisory on Auto-Run

You might have seen the advisory of the US-CERT titled Microsoft Windows Does Not Disable AutoRun Properly – if not, you will definitely have seen one of the articles covering this issue and telling you that our advice on how to prevent Conficker is flawed.

This statement is not quite true the way it came out initially and US-CERT in the meantime already adjusted their advisory:

Our advice in https://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/91525.mspx?mfr=true works if you apply https://support.microsoft.com/kb/953252

US-CERT already updated their advisory:

Update:

Microsoft has provided support document KB953252 , which describes how to correct the problem of NoDriveTypeAutoRun registry value enforcement. After the update is installed, Windows will obey the NoDriveTypeAutorun registry value. Note that this fix has been released via Microsoft Update to Windows Vista and Server 2008 systems as part of the MS08-038 Security Bulletin. Windows 2000, XP, and Server 2003 users must install the update manually. Our testing has shown that installing this update and setting the NoDriveTypeAutoRun registry value to 0xFF will disable AutoRun as well as the workaround described above.

Roger

Comments

  • Anonymous
    January 24, 2009
    Microsoft should have issued a security bulletin including the KB953252 fix for XP.  Then people concerned about security would have known about it.

  • Anonymous
    February 04, 2009
    The main problem on Windows XP systems is, that KB953252 is not beeing offered as an optional update at leasr via Windows Update. You need to know about the update to even consider installing it. So, offering KB953252 (or ist's successor(?) KB955704) via the Windows/Auto Update distribution channels for Windows XP "may" be needed. FWIW, Freudi

  • Anonymous
    May 04, 2009
    How to correct “disable Autorun registry key” enforcement in Windows The registry key guidance that is offered in Technet article 91525 (www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/91525.mspx?mfr=true) did not correctly disable AutoRun features. After you set the registry keys to disable these features as described in this Technet article, the AutoRun capabilities, the Double Click feature, and the Contextual Menu feature continue to function as if they were not set. This article describes how to obtain updates that correct these registry key settings.

  • Anonymous
    December 30, 2009
    I am also aware that Microsoft has provided a support document, which describes how to correct the problem of NoDriveTypeAutoRun registry value enforcement.  I have used it and it works.

  • Anonymous
    September 23, 2012
    Find business security and business surveillance products from DIS Group. Get expert advice, a free safety and security review, and security products. Your safety and security needs will be met with DIS Group’s Security System’s reliable service and latest technologies. Please Visit: <a href="http://www.disgroups.com">Philadelphia</a>