topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Thursday April 18, 2024, 7:13 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: [Security] issues with Vista & Win7 gadgets  (Read 2561 times)

tomos

  • Charter Member
  • Joined in 2006
  • ***
  • Posts: 11,961
    • View Profile
    • Donate to Member
[Security] issues with Vista & Win7 gadgets
« on: July 19, 2012, 02:44 AM »
Via Windows Secrets -
Kill those Vista and Win7 gadgets now!

Apparently there are large security issues with the sidebar, and gadgets in general.

Although the vulnerability in gadgets has existed for years, two security researchers are shedding some new light on the threat. At next week’s annual hacker gathering in Las Vegas — Black Hat USA 2012 (more info) — Mickey Shkatov and Toby Kohlenberg will deliver their presentation, “We have you by the gadgets.” As is common for Black Hat presentation pre-announcements, there are as yet few details. But Shkatov and Kohlenberg promise, “We will be talking about the Windows gadget platform and what nastiness can be done with it, how are gadgets made, how are they distributed, and, more importantly, their weaknesses. … As a result, there [are] a number of interesting attack vectors that are interesting to explore and take advantage of. We will be talking about our research into creating malicious gadgets, misappropriating legitimate gadgets, and the sorts of flaws we have found in published gadgets.”

Microsoft have a fix if you want to disable them all:
http://support.microsoft.com/kb/2719662
Tom

IainB

  • Supporting Member
  • Joined in 2008
  • **
  • Posts: 7,540
  • @Slartibartfarst
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: [Security] issues with Vista & Win7 gadgets
« Reply #1 on: July 27, 2012, 10:35 AM »
Just a belated thanks for posting this.
I have disabled the gadgets on 2 laptops, using the disable FixIt on Microsoft's website.
I have also disabled the gadget service's communication via Windows 7 Firewall Control.