Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • WinDeals
  • E-Books
  • Lounge
  • Polls
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Woody's Windows>Microsoft improves AutoRun and AutoPlay features

Microsoft improves AutoRun and AutoPlay features

Posted on May 21, 2009 by Woody Leonhard in Woody's Windows
Tweet

Woody Leonhard 1 Microsoft improves AutoRun and AutoPlay features By Woody Leonhard

By disabling AutoRun and changing the wording of the top entry in the AutoPlay dialog, Microsoft has made the forthcoming Windows 7 more secure without significantly inconveniencing Windows customers.

The company also promises to make similar security changes in AutoRun and AutoPlay available for XP and Vista users, although it hasn’t yet said when this will happen.


The problems with how AutoRun and AutoPlay work

The Conficker worm, which was widely hyped in the last couple of months, illustrated a huge security hole in Windows’ AutoRun and AutoPlay functions. In a nutshell, AutoRun automatically executes instructions it finds when a removable drive is inserted, and AutoPlay automatically plays audio and video files. Either function can silently install malware if an infected disc or USB drive is used.

One major problem involved a small text file known as autorun.inf. WS contributing editor Susan Bradley’s March 5 Top Story explained some steps Microsoft has taken to mitigate the security threat. She also explained why the official fix fails to completely protect Windows systems. (The patch finally makes it possible for Windows users to easily disable AutoRun — not just appear to have turned it off — but the patch doesn’t actually disable anything.)

Last month, Microsoft announced on its Security Response Center blog that the company had decided to disable AutoRun in Windows 7. Microsoft has also changed the way AutoPlay works. The details, as provided on the Engineering Windows 7 blog, are a bit difficult to follow, but here’s how things stand right now:

As I explained in my Jan. 22 Top Story, a few well-written lines in an autorun.inf file on a USB drive, CD, or DVD can trick just about anyone into running a hacker’s program. Such a custom-made autorun.inf file causes Windows to display an option titled Open folder to view files at the top of the AutoPlay menu. (See Figure 1.) In reality, if you click this option, the hacker’s program will silently install rather than simply running a file viewer. It’s easy for users to overlook the fact that this option is located in the dialog box’s Install or run program section.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Do-It-Yourself Autorun CDs On XP And Other Win Versions
  2. How to protect yourself against autoplay discs
  3. Microsoft flubs a way to disable AutoRun in XP
  4. Free Microsoft AutoPlay Repair Tool
  5. One quick trick prevents AutoRun attacks
= Paid content

All Windows Secrets articles posted on 2009-05-21:

  • Bonus Find a great company whether you need it or not
  • Top Story Get all security patches without WGA nightmares
  • Known Issues WGA affects legitimate MS customers differently
  • Wacky Web Week This food’s out to attack more than your heart
  • LangaList Plus Fix power-management glitches in XP and Vista
  • Best Software Software improves lighting on digital photos
  • Woody's Windows Microsoft improves AutoRun and AutoPlay features
  •  Show all articles on a single page
Woody Leonhard

About Woody Leonhard

Woody Leonhard is a Windows Secrets senior editor and a senior contributing editor at InfoWorld. His books on Windows and Office include the award-winning Windows 7 All-In-One For Dummies. His many writings cast a critical eye on the latest industry shenanigans.
View all posts by Woody Leonhard →

WinDeals

WinDeals offers subscribers regular discounts — of up to 50 percent off — on software and technology products. Read moreยป

View current deals
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.56
  • LizaMoon infection: a blow-by-blow account 4.46
  • RPV: Win7′s least-known data-protection system 4.35
  • Recovery: the last step in total data security 4.31
  • The sorry tale of the (un)Secure Sockets Layer 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Get wired performance from your Wi-Fi network 4.24
  • Caution: Bumps in the road to IPv6 4.23
  • Patch Watch adds problem-patch update chart 4.23
  • ZeuS Trojan reinvents itself as bots rock on 4.22
  • Pros and cons of a ‘keyfile’ password 4.21
  • April brings showers of browser patches 4.20
  • Readers comment on the LizaMoon infection story 4.20
  • Office 2007 gets its final service pack 4.19
  • The advanced system-recover toolkit 4.18
  • Putting Registry-/system-cleanup apps to the test 4.18
  • One year and 99 security bulletins later 4.18
  • Don’t pay for software you don’t need — Part 3 4.17
  • What to do when Windows refuses to boot 4.17
  • Make the most of Windows 7′s Libraries 4.16
  • Keeping you up to date: say no to .NET — again 4.16
  • Internet Explorer gets another round of patches 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Big-time Wi-Fi security for the small office 4.14
  • Office File Validation patch leads to problems 4.14
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb