Blog Reactions
Infosec Ramblings: Interesting Information Security Bits for 11/03/2009
Signaling IT: Sophos' Windows 7 Infection Test
eWeek - RSS Feeds: Windows 7 UAC Ineffective Security Solution for Malware, Sophos Says
| Sophos says Windows 7 susceptible to viruses http://bit.ly/21QJ2Y 7 days ago |
| Sophos says Windows 7 vulnerable to viruses http://bit.ly/y7S8z #Windows7 #Viruses #vulnerability 11 days ago |
| Sophos: Windows 7 vulnerable to 8 out of 10 viruses http://bit.ly/y7S8z 12 days ago |
Interesting Information Security Bits for 11/03/2009
Infosec Ramblings —
Good afternoon everybody! I hope your day is going well.
Here are today’s Interesting Information Security Bits from around the web.
A few days ago I pointed out an article that discussed some issues with the default settings for UAC in Windows 7. This article shows that the criticism in the other article is well earned.
Windows 7 vulnerable to 8 out of 10 viruses | Chester Wisniewski’s Blog
Tags: ( virus windows-7 )
Interested in cross-subdomain cookie attacks? Check out the paper that mckt wrote. ...
Sophos' Windows 7 Infection Test
Signaling IT —
... Chester Wisniewski, Senior Security Advisor for Sophos Canada, yesterday published on his blog a rather damning account of Windows 7 security and User Account Control (UAC). ...
Windows 7 UAC Ineffective Security Solution for Malware, Sophos Says
eWeek - RSS Feeds —
... in the security community, and Sophos Senior Security Advisor Chester Wisniewski said his test proves Microsoft took it a step too far. I ...
Sophos Tests Show Windows 7 Still Needs Anti-Malware (Duh!)
Security Watch —
Test results published by Sophos show that Windows 7's (UAC) User Account Control does not prevent execution of 8 of 10 malware samples they chose. The conclusion: Windows 7 still needs anti-malware protection.
I hesitated to write about this for a while because it's such a phony story. Nobody ever claimed that Windows 7 didn't require anti-malware or that UAC, per se, stops malware from executing. Furthermore, details of the tests and the malware selected are lacking in Sophos's write-up. Clearly, at least some of the malware samples are rogue anti-malware ...
Windows 7's UAC Slammed by Sophos
Redmond Report —
... . However, the issue for Chester Wisniewski, a Sophos security staffer, was purely about the security protection afforded by UAC in Windows 7. "UAC's default configuration is not effective at protecting a PC from modern malware," Wisniewski wrote in a Sophos blog post last week. Sophos came to that conclusion based its testing of UAC. Those tests involved a clean install of Windows 7, running it without antivirus protection. Next, the Sophos team added "10 unique samples" of malware to the PC. The UAC failed to block eight of the ten viruses from running, according to the ...

