Security Now 187

Security Now
Episode 187

Security Now 187: Fixing Autorun

News & Errata

Name - Security Now

  • Windows updates this week.
  • Still no fix for the Microsoft Excel flaw, rumour is it will be patched out of cycle.
  • Parsing bug in Windows Metafile.

  • Adobe acrobat V9 has been patched. No patch for any prior versions yet expected around the 18th March, 2009.
  • Rumours are that non Adobe PDF readers, such as Foxit, may also be vulnerable to the same exploit.
  • Disabling JavaScript is no longer a way to prevent this exploit.

  • Updates for Mozilla software available.

  • Updates for Opera available.

  • Updates for Winamp available.
  • Exploiting software is now big business.
  • Foxit Software claims that Foxit Reader is not vulnerable to the Adobe Reader exploit but there is an update available.

  • All top level .gov DNS servers are now running DNS SEC.

  • The new tigger trojan specifically targets employees and clients of stock brokers

  • Conficker worm discovered in November 2008, infected 11.4 million PC's.
  • Now at major version C.
  • Hard to contain as they use an algorithm to determine what domain name to go to on a given day to receive instructions.
  • The original version could deal with 250 domains and researchers had to discover these domains and take them out of service first.
  • The C version increases it to 50,000 domains.
  • Today 3 million IP addresses are contacting these domains a day.
  • The B version spreads through open network shares by trying 240 common passwords and can propagate through USB memory sticks by infecting the autorun.inf file.
  • Until the February update even if autorun was disabled it could still run.

Spinrite Story

A listener has used Spinrite to fix friends computers but not his. He runs spinrite on his drives quarterly and on new drives before they are put to use. So far he has never had any issues with his drives.

Fixing Autorun

  • Before the update autorun configuration did not work. I.e. even if you disabled it you could force media to autorun.
  • Microsoft never offered the autorun update through windows update for any OS other than Server 2008 and Vista due to fearing it would break a lot of things for people. The B version of the Conficker worm exploiting the problems with autorun prompted them to publish the patch through windows update.
  • "Honour autorun setting = 1" as default after the update so that it still behaves in the old manner even with the update to minimise the amount of things that will break for people.

Auto run is controlled by a registry key called "NoDriveTypeAutorun" and the types that you don't want to autorun for are encoded in bits in the value of this registry key.

  • The 1 hex bit in the value disables Autoplay on drives of unknown type, the hex 80 bit does the same thing.
  • USB and Firewire drives are disabled if the hex 4 bit is set
  • Fixed hard drives are disabled by the hex 8 bit
  • CD-ROMs are governed by the 20 hex bit
  • RAM disks by the 40 hex bit.
  • Microsoft claim if you set the value to FF it disables everything. However this is not true.
  • You also need to set the value to FF in two other places.
  • The key in "current users" overrides any other setting.
  • XP, Vista and Server 2008 set this value to hex 91 as default which means unknown drives and network drives are disabled.
  • Windows 2000 and Server 2003 set this value to hex 95 as default which means unknown drives, network drives and removable drives are disabled.


Disabling autorun:




See Microsoft's Knowledge Base Article KB967715, microsoft provides easy executables to enable/disable autorun.


