New Windows Flaw Allows Hack

MHTML Vulberability

Windows (ALL current editions) is vulnerable to a hack through it’s MIME HTML handling protocol. This vulnerability would allow malicious code to be run through Internet Explorer and through Opera. This is a variant of XSS (Cross Site Scripting).

Firefox requires an add-on to read and write MHTML files. In it’s default configuration it is not vulnerable, Safari and Chrome are not either.

Microsoft recommended that users lock down the MHTML protocol handler by running a "Fixit" tool it's made available. This is not a patch. That will require more time to develop because this is a Windows vulnerability, not an iE one.

The Fixit tool can be accessed from Microsoft's support site . It has the undo tool there as well for when the real fix comes. This edits the registry and automatically makes a restore point before installing.

The current list of vulnerabilities not fixed by MS can be found HERE.

The CSS flaw I reported on in December can be addressed with a work around you can find HERE. The uninstall for it can be found HERE.

50,053 views 25 replies
Reply #1 Top

Would it be a good idea to go for it even if Firefox is not the open door?

Reply #3 Top

Thanks Doc!!! :) ;)

Reply #4 Top

Then that's what I'm gonna do. One other question Doc. I created a user account for everyday use, not an administrator one, but mistakenly gave it admin status. How can I change that? There doesn't seem to be a way. OT I know but I'm trying to close back doors.

Reply #5 Top

Harley, You're welcome. :)

Uvah:

Click start and type secpol.msc

This will open up the W7 Security Policy Editor, now browse to Security Settings, Local Policy, Security Options

At the top double click for both the administrator and guest account, choose enabled. Close all windows and restart Windows 7.

You are now able to login to 7 as administrator or guest. A good option is to rename those accounts to make it harder for hackers/friends you don't trust to find your precious login.

After enabling these accounts you should set a password as well, click start then type in cmd, then type net user administrator "password" without the quotes of course, you can do the same with the guest account or any other accounts, for more info on net user type net user /? or net /?

Reply #6 Top

Typed it and got this..... no items match. Did it twice and got the same thing.

Reply #7 Top

Don't know why, Uvah unless you aren't logged on as the Admin.

Reply #8 Top

I am believe it or not. Under my nic as Administrator, password protected. I logged off then logged back on. Even changing it back to my name makes no difference.

Reply #9 Top

Only you, Uvah. Suggestion?

PM yrag. We need some entertainment.  ;)

Reply #10 Top

I don't think so.

Reply #11 Top

I don't think so.

No balls, no golf.

secpol.msc

You don't have it.

 

Control Panel\All Control Panel Items\User Accounts - Change account type

Reply #12 Top

Thought he had W7 Pro, yrag.

Reply #13 Top

I posted in another thread I have home premium. I did change account types in control panel. That I know how to do. Its just that I wanted to change the second user account type and remove admin rights from it. No sense having two of them. I'm getting drawn into this anyway. Okay ...... tell me where I screwed up.

Reply #14 Top

I posted in another thread I have home premium.

Shame on you Doc for not taking notes.....

 

Control Panel\All Control Panel Items\User Accounts

Post a snapshot of that panel.

Reply #15 Top

 

EDIT:

nevermind that post......lol.......didn't READ that he doesn't have Win7 pro  doh!  :blush:

 

Reply #16 Top

It has the undo tool there as well for when the real fix comes.

Crap.  Hope I get that part right.  Have visions of doing the final patch without undoing the temporary one.

Reply #17 Top

 

Uvah,

If you don't have at least one account as an "administrator" it won't let you take admin rights away from another.  My question is........are you sure that there is at least one admin user in the list?

Reply #18 Top

Okay. Next.

 

Reply #19 Top

I strongly urge a backup.



Control Panel\All Control Panel Items\User Accounts\Manage Accounts\Create New Account

Create a second Admin account (no password). Hit 'Create account'

Click on the new account and enter a different password twice.(ignore the warning).

DO NOT CLOSE DIALOG BOX

Click on original Admin account and change to 'Standard'

Close. Log off/log on to new account

+1 Loading…
Reply #21 Top

First things first. All done. Problem solved. One admin, one standard and it didn't even hurt. Thank you yrag.

@Doc .... got it.

Reply #22 Top

Good news! Gary, Thanks for your help. :)

Reply #23 Top

What I didn't expect was to have to rebuild my 'desktop' from scratch. Going back after all the .exe's and stuff. Tons-a-fun. lol

Reply #24 Top

I hate workarounds - not for me.  They are usually simple - but have you tried talking your aunt Mabel through them>?????

Thanks for the tip.  I hope MS gets a patch quickly.

Reply #25 Top

This is a good place to post this. Just now I got a message about an update for firefox called Update Browser. As the author was verified I allowed it to install then I checked out the url http://www.nu-browser.com and got a 404 in return. I quickly uninstalled it. It may or not be genuine but I wasn't going to take the chance.