<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows Vista Vulnerable to StickyKeys Backdoor</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor</link>
	<description></description>
	<lastBuildDate>Fri, 18 May 2012 09:34:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Abe</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-191449</link>
		<dc:creator>Abe</dc:creator>
		<pubDate>Fri, 16 Dec 2011 00:11:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-191449</guid>
		<description>so if a laptop has already been tempered with this &quot;stick keys backdoor&quot;, how to countermeasure it? or how to  know what files/folder has been exploit? Also that would almost make the keyboard useless with all that CAPS and no numbers!!!! I  am having this problem now, Would someone please help me to solve it?  Thanks a lot!</description>
		<content:encoded><![CDATA[<p>so if a laptop has already been tempered with this &#8220;stick keys backdoor&#8221;, how to countermeasure it? or how to  know what files/folder has been exploit? Also that would almost make the keyboard useless with all that CAPS and no numbers!!!! I  am having this problem now, Would someone please help me to solve it?  Thanks a lot!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mcgrimus</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7947</link>
		<dc:creator>mcgrimus</dc:creator>
		<pubDate>Tue, 05 May 2009 12:46:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7947</guid>
		<description>&quot;Windows Vista Vulnerable to StickyKeys Backdoor&quot;

Am I really the first one here to say, &quot;That&#039;s what she said!&quot; to this??</description>
		<content:encoded><![CDATA[<p>&#8220;Windows Vista Vulnerable to StickyKeys Backdoor&#8221;</p>
<p>Am I really the first one here to say, &#8220;That&#8217;s what she said!&#8221; to this??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Someone</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7946</link>
		<dc:creator>Someone</dc:creator>
		<pubDate>Sat, 02 May 2009 06:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7946</guid>
		<description>Works on 100% of campus computers.  Kind of scary the potential information someone nefarious can get.  Keylogger anyone?</description>
		<content:encoded><![CDATA[<p>Works on 100% of campus computers.  Kind of scary the potential information someone nefarious can get.  Keylogger anyone?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mervin</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7942</link>
		<dc:creator>Mervin</dc:creator>
		<pubDate>Sun, 29 Jun 2008 18:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7942</guid>
		<description>&quot;an attacker can use this method to bypass login on terminal servers and workstations with the remote desktop enabled. Since no third-party tools are being installed on the system and we are using Microsoftâ€™s own files to achieve this, it will be difficult to detect for a typical administrator.&quot;

I just discovered couple of terminal servers in our university network where one could remote backdoor into using this Sticky-key backdoor method with full SYSTEM rights. So this technique is being used by bad guys and its shocking that M$ still don&#039;t protect sethc.exe and utilman.exe with windows file protection!!!</description>
		<content:encoded><![CDATA[<p>&#8220;an attacker can use this method to bypass login on terminal servers and workstations with the remote desktop enabled. Since no third-party tools are being installed on the system and we are using Microsoftâ€™s own files to achieve this, it will be difficult to detect for a typical administrator.&#8221;</p>
<p>I just discovered couple of terminal servers in our university network where one could remote backdoor into using this Sticky-key backdoor method with full SYSTEM rights. So this technique is being used by bad guys and its shocking that M$ still don&#8217;t protect sethc.exe and utilman.exe with windows file protection!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7941</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Sat, 14 Jun 2008 17:20:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7941</guid>
		<description>Or, you could just turn off StickyKeys altogether. That would just about solve that problem.</description>
		<content:encoded><![CDATA[<p>Or, you could just turn off StickyKeys altogether. That would just about solve that problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rory</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7940</link>
		<dc:creator>Rory</dc:creator>
		<pubDate>Wed, 11 Jun 2008 20:46:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7940</guid>
		<description>WRONG!
You don&#039;t need admin access. Pop in Auditor or backdoor linux boots and in five minutes flat you can have the &#039;sploit in place and running.</description>
		<content:encoded><![CDATA[<p>WRONG!<br />
You don&#8217;t need admin access. Pop in Auditor or backdoor linux boots and in five minutes flat you can have the &#8216;sploit in place and running.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GhaFear</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7938</link>
		<dc:creator>GhaFear</dc:creator>
		<pubDate>Tue, 27 May 2008 16:12:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7938</guid>
		<description>I see a point, as far as the exe can&#039;t be replaced unless you have admin access.

But I have a problem with the login and loading a desktop. There should no way under any situation it being able to bypass it.

GhaFear</description>
		<content:encoded><![CDATA[<p>I see a point, as far as the exe can&#8217;t be replaced unless you have admin access.</p>
<p>But I have a problem with the login and loading a desktop. There should no way under any situation it being able to bypass it.</p>
<p>GhaFear</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JesusE.</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7937</link>
		<dc:creator>JesusE.</dc:creator>
		<pubDate>Tue, 08 Apr 2008 07:52:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7937</guid>
		<description>Sometimes the Stickykeys dialog box appear when no body are using the computer, as if someone had pressed 5 times the shiftkey. Will be some unauthorized external access?</description>
		<content:encoded><![CDATA[<p>Sometimes the Stickykeys dialog box appear when no body are using the computer, as if someone had pressed 5 times the shiftkey. Will be some unauthorized external access?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jerry</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7936</link>
		<dc:creator>Jerry</dc:creator>
		<pubDate>Fri, 22 Feb 2008 07:49:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7936</guid>
		<description>&quot;As for the usability. I can see some uses that this can be utalized for. This is just but one of many &#8220;Bugs&#8221; that Microsoft has in it s OS. Vista, XP . â€¦. etc..&quot;

This is not a Microsoft specific &quot;BUG&quot;,  you can do the same on Linux, BSD, ....   PS: I&#039;m not a M$ fans.

So the first security step is to lock your system physically.</description>
		<content:encoded><![CDATA[<p>&#8220;As for the usability. I can see some uses that this can be utalized for. This is just but one of many &ldquo;Bugs&rdquo; that Microsoft has in it s OS. Vista, XP . â€¦. etc..&#8221;</p>
<p>This is not a Microsoft specific &#8220;BUG&#8221;,  you can do the same on Linux, BSD, &#8230;.   PS: I&#8217;m not a M$ fans.</p>
<p>So the first security step is to lock your system physically.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Revan</title>
		<link>http://blogs.mcafee.com/mcafee-labs/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-2#comment-7935</link>
		<dc:creator>Revan</dc:creator>
		<pubDate>Fri, 21 Sep 2007 08:37:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=218#comment-7935</guid>
		<description>You know... being a network engineer for a little while have thought me one thing. The fact that I have a physical and unsupervised access to the machine is a security concern for a client, for the only thing between their business being secured or unsecured is my business ethics.

Exploits that require modifications and other things are really waste of time as anyone who wants your data can obtain it very easily anyway.

I always tell my clients that if someone wants to steal their data they will drive a truck through the front door and walk away with their server, much cheaper, more efficient and less time consuming.

Kind Regards</description>
		<content:encoded><![CDATA[<p>You know&#8230; being a network engineer for a little while have thought me one thing. The fact that I have a physical and unsupervised access to the machine is a security concern for a client, for the only thing between their business being secured or unsecured is my business ethics.</p>
<p>Exploits that require modifications and other things are really waste of time as anyone who wants your data can obtain it very easily anyway.</p>
<p>I always tell my clients that if someone wants to steal their data they will drive a truck through the front door and walk away with their server, much cheaper, more efficient and less time consuming.</p>
<p>Kind Regards</p>
]]></content:encoded>
	</item>
</channel>
</rss>

