Microsoft finally says adios to Autorun

Worm bait purged from older Windows


After a decade of abuse, Autorun is finally being retired in older versions of Windows.

On Tuesday, Microsoft began pushing an update that changes the way Windows Server 2008 and earlier versions of the OS respond when USB thumb drives and other portable media are plugged in. Until now, those versions dutifully executed code embedded in autorun.inf files without first prompting the user. The default behavior provided a convenient way to propagate malware such as Conficker, which hijacked the feature to spread itself each time an infected drive was inserted.

Microsoft finally nixed Autorun in Windows 7, but until now, users of earlier versions had to muck about in the Windows registry or install a special fix it to turn it off. Adding the change to the official Windows Update mechanism means millions of users will turn it off automatically.

“We feel like now is the right time across the industry to be able to push this change out and have a pretty substantial impact on how malware spreads,” Jerry Bryant, group manager in Microsoft's Response Communications, told The Reg. “This is really something that will help to further protect the ecosystem.”

Bryant said the main reason Microsoft didn't retire Autorun sooner was the resistance from some partners who rely on the feature to install programs that accompany their hardware. Over the past few years technologies such as in the U3 functionality found on many thumb drives has provided alternatives.

The "Important, non-security update" was pumped into the pipeline on the same day Microsoft issued 12 security bulletins fixing 22 vulnerabilities in Windows, Office, Internet Explorer and IIS. Three of the bulletins are rated critical. Sans has a helpful breakdown here.

As we've pointed out before, the changes to Autorun still don't go far enough. CDs and DVDs by default still automatically execute code when inserted. Adam Shostack, a program manager for Microsoft's Trustworthy Computing group, said here that Microsoft has yet to see in-the-wild attacks that exploit Autorun on “shiny media.”

Weighing the minimal amount of convenience from Autorun against its potential for bad things to happen, we still think it's a bad idea, even for CDs and DVDs. Those who agree can turn it off entirely by following the instructions here. ®


Other stories you might like

  • Experts: AI should be recognized as inventors in patent law
    Plus: Police release deepfake of murdered teen in cold case, and more

    In-brief Governments around the world should pass intellectual property laws that grant rights to AI systems, two academics at the University of New South Wales in Australia argued.

    Alexandra George, and Toby Walsh, professors of law and AI, respectively, believe failing to recognize machines as inventors could have long-lasting impacts on economies and societies. 

    "If courts and governments decide that AI-made inventions cannot be patented, the implications could be huge," they wrote in a comment article published in Nature. "Funders and businesses would be less incentivized to pursue useful research using AI inventors when a return on their investment could be limited. Society could miss out on the development of worthwhile and life-saving inventions."

    Continue reading
  • Declassified and released: More secret files on US govt's emergency doomsday powers
    Nuke incoming? Quick break out the plans for rationing, censorship, property seizures, and more

    More papers describing the orders and messages the US President can issue in the event of apocalyptic crises, such as a devastating nuclear attack, have been declassified and released for all to see.

    These government files are part of a larger collection of records that discuss the nature, reach, and use of secret Presidential Emergency Action Documents: these are executive orders, announcements, and statements to Congress that are all ready to sign and send out as soon as a doomsday scenario occurs. PEADs are supposed to give America's commander-in-chief immediate extraordinary powers to overcome extraordinary events.

    PEADs have never been declassified or revealed before. They remain hush-hush, and their exact details are not publicly known.

    Continue reading
  • Stolen university credentials up for sale by Russian crooks, FBI warns
    Forget dark-web souks, thousands of these are already being traded on public bazaars

    Russian crooks are selling network credentials and virtual private network access for a "multitude" of US universities and colleges on criminal marketplaces, according to the FBI.

    According to a warning issued on Thursday, these stolen credentials sell for thousands of dollars on both dark web and public internet forums, and could lead to subsequent cyberattacks against individual employees or the schools themselves.

    "The exposure of usernames and passwords can lead to brute force credential stuffing computer network attacks, whereby attackers attempt logins across various internet sites or exploit them for subsequent cyber attacks as criminal actors take advantage of users recycling the same credentials across multiple accounts, internet sites, and services," the Feds' alert [PDF] said.

    Continue reading

Biting the hand that feeds IT © 1998–2022