Autorun.ini security hole

F

foo

The Windows Secrets site has article about how to prevent
systems from executing autorun.ini files on removable media.

http://windowssecrets.com/comp/071108

It sounds like a significant hole to me. I am surprised that
this hasn't come up long ago.

The article refers to XP and Vista only. Woody Leonhard has
long paroted the M$ line that Windows 98 doesn't matter any more
and is a long time Opera denier.

The article contains a registry update file

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\IniFileMapping\Autorun.inf]
@="@SYS:DoesNotExist"

Years I set autoinsert off in device manager and that kept CDs
from going off.

Searching my registry I didn't find these keys. (I did find a
ifilemapping under Kodak software that looked immaterial)

Questions.

1. Do the apparent ways of starting an autorun.ini in XP and
Vista, whatever they are, get around auto insert notification
unchecked in 98? Or, does that setting remain secure?

2. Are autoruns on flash drives a problem in 98? Is there an
equivalent fix for 98?
 
D

Dan

Here is Chris Quirke's Website and it has great ways to minimize any risks
and tighten down Windows 9x operating systems.

http://users.iafrica.com/c/cq/cquirke/riskfix.htm#RegEdit

"foo" wrote:

> The Windows Secrets site has article about how to prevent
> systems from executing autorun.ini files on removable media.
>
> http://windowssecrets.com/comp/071108
>
> It sounds like a significant hole to me. I am surprised that
> this hasn't come up long ago.
>
> The article refers to XP and Vista only. Woody Leonhard has
> long paroted the M$ line that Windows 98 doesn't matter any more
> and is a long time Opera denier.
>
> The article contains a registry update file
>
> REGEDIT4
> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
> NT\CurrentVersion\IniFileMapping\Autorun.inf]
> @="@SYS:DoesNotExist"
>
> Years I set autoinsert off in device manager and that kept CDs
> from going off.
>
> Searching my registry I didn't find these keys. (I did find a
> ifilemapping under Kodak software that looked immaterial)
>
> Questions.
>
> 1. Do the apparent ways of starting an autorun.ini in XP and
> Vista, whatever they are, get around auto insert notification
> unchecked in 98? Or, does that setting remain secure?
>
> 2. Are autoruns on flash drives a problem in 98? Is there an
> equivalent fix for 98?
>
 
Back
Top Bottom