Gadgets Could Allow Remote Code Execution

marsmimar

New member
Guru
Gold Member
VIP
Local time
4:36 PM
Messages
6,973
Location
South Central Texas

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
***sigh***

I searched in News as well as System Security. Didn't see Shawn's thread. Isn't the first time that happened. Most likely won't be the last, either. :o
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Been there, done that :rolleyes:
Shawn's too quick for us mortal's :zip:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
What it's funny about that post is that, when M$ finds a problem, instead of solving it and prevent any vulnerability, they just decide to blow them off and nuke one of the most distinctive characteristics of Win7.

Does anyone know if it's really a problem in the gadgets themselves or in the runtime they use?? (and since they are HTML after all, I suppose they really run in the virus-friendly IE). Also, this problem most likely existed since the very first version of Win Vista and nobody has really problems isn't it? So, why would I disable them altogether?

Also, M$ fails to point in their article the security mitigations we can take to prevent problems without sacrificing functionality. What about UAC? What about limited user rights? What about antiviruses? What about firewalls? What about running in low integrity? It's not crazy that a reasonably protected computer is mostly immune to the Windows design flaws.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Sattelite A665-S6092
OS
Windows 7 Ultimate x64
CPU
Intel Core i7-740QM
Memory
8 GB DDR3
Graphics Card(s)
NVIDIA GeForce 330GT
Screen Resolution
1366x768
Hard Drives
Samsung 840 SSD 500GB
1TB USB3 external HD
Cooling
Coolermaster Notepal U3 notebook cooling pad
Internet Speed
3mbps ASDL
Antivirus
ClamWin 0.98.7
Browser
Opera 12.17 x86 (main), Firefox 38 (sec), IE11 (last resort)
Since I run as admin and have several gadgets - no problems yet - I will shortly be expecting my first malware and will report back when I have stopped crying all night!

:cry: :cry: :cry: :cry: :huh: :eek: :D :D :D :D :D
 

My Computer

Computer Manufacturer/Model Number
Compaq desktop
OS
Windows 7 x64 SP1
CPU
Athlon II x2 215
Memory
4.0 GB
Graphics Card(s)
Onboard
Sound Card
Creative SB X-Fi Titanium HD (nice)
Monitor(s) Displays
24" Dell LCD
Screen Resolution
1900 x 1200
Hard Drives
320 GB, 500 GB and 750 GB 7200 rpm
PSU
430w
Keyboard
USB
Mouse
USB
Internet Speed
approx 10 Mbps
Since I run as admin and have several gadgets - no problems yet - I will shortly be expecting my first malware and will report back when I have stopped crying all night!

:cry: :cry: :cry: :cry: :huh: :eek: :D :D :D :D :D

I bet you'll not notice any difference at all. The bug have been there for years and nobody has ever cried because of them.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Sattelite A665-S6092
OS
Windows 7 Ultimate x64
CPU
Intel Core i7-740QM
Memory
8 GB DDR3
Graphics Card(s)
NVIDIA GeForce 330GT
Screen Resolution
1366x768
Hard Drives
Samsung 840 SSD 500GB
1TB USB3 external HD
Cooling
Coolermaster Notepal U3 notebook cooling pad
Internet Speed
3mbps ASDL
Antivirus
ClamWin 0.98.7
Browser
Opera 12.17 x86 (main), Firefox 38 (sec), IE11 (last resort)
Since I run as admin and have several gadgets - no problems yet - I will shortly be expecting my first malware and will report back when I have stopped crying all night!

:cry: :cry: :cry: :cry: :huh: :eek: :D :D :D :D :D

I bet you'll not notice any difference at all. The bug have been there for years and nobody has ever cried because of them.

That has put my mind at rest although I wasn't/am not really expecting much to happen.

:roflmao:
 

My Computer

Computer Manufacturer/Model Number
Compaq desktop
OS
Windows 7 x64 SP1
CPU
Athlon II x2 215
Memory
4.0 GB
Graphics Card(s)
Onboard
Sound Card
Creative SB X-Fi Titanium HD (nice)
Monitor(s) Displays
24" Dell LCD
Screen Resolution
1900 x 1200
Hard Drives
320 GB, 500 GB and 750 GB 7200 rpm
PSU
430w
Keyboard
USB
Mouse
USB
Internet Speed
approx 10 Mbps
Well, I can't say for sure how this happened, but...
I run Win7 with Comodo Firewall, Avast Antivirus, and Windows Defender.
Left my system on overnight running torrents. This morning just happened to notice Comodo Firewall was not running. WTF? I am certain I did not turn it off. All the same, went about looking through the morning messages.
Then my system locks up. It happens sometimes. Cold reboot. Windows comes up, I enter pw, all appears normal until that very last part when Windows loads gadgets (heed a warning? me?), then the system freezes, screen goes pale like someone draped a thin tissue over the screen. I do another cold reboot. Same. It works like it always does, until the last few seconds when the gadgets should load. Freeze happens again. I notice the hard disk activity light is not flashing, as it usually does while the gadgets load.
I wasn't in the mood for forensic research, so restored a backup from 10 days before. This bu was before MS put out that load of recent updates (I think it was Aug 14).
After restore the first thing I did was shut off Gadget's sidebar.

Even though these holes have been there for years the recent publicity could very well attract people with nothing better to do.
 

My Computer

OS
Windows 7 Ultimate 32bit
Well, I can't say for sure how this happened, but...
I run Win7 with Comodo Firewall, Avast Antivirus, and Windows Defender.
Left my system on overnight running torrents. This morning just happened to notice Comodo Firewall was not running. WTF? I am certain I did not turn it off. All the same, went about looking through the morning messages.
Then my system locks up. It happens sometimes. Cold reboot. Windows comes up, I enter pw, all appears normal until that very last part when Windows loads gadgets (heed a warning? me?), then the system freezes, screen goes pale like someone draped a thin tissue over the screen. I do another cold reboot. Same. It works like it always does, until the last few seconds when the gadgets should load. Freeze happens again. I notice the hard disk activity light is not flashing, as it usually does while the gadgets load.
I wasn't in the mood for forensic research, so restored a backup from 10 days before. This bu was before MS put out that load of recent updates (I think it was Aug 14).
After restore the first thing I did was shut off Gadget's sidebar.

Even though these holes have been there for years the recent publicity could very well attract people with nothing better to do.

Perhaps the updates affected your system but they didn't with mine and I use several gadgets including system control (shutdown, restart and cmd buttons), applauncher, network meter and cpu/memory meter all working perfectly.

;) :huh: :)
 

My Computer

Computer Manufacturer/Model Number
Compaq desktop
OS
Windows 7 x64 SP1
CPU
Athlon II x2 215
Memory
4.0 GB
Graphics Card(s)
Onboard
Sound Card
Creative SB X-Fi Titanium HD (nice)
Monitor(s) Displays
24" Dell LCD
Screen Resolution
1900 x 1200
Hard Drives
320 GB, 500 GB and 750 GB 7200 rpm
PSU
430w
Keyboard
USB
Mouse
USB
Internet Speed
approx 10 Mbps
Back
Top