<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows Vista Vulnerable to StickyKeys Backdoor</title>
	<atom:link href="http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/</link>
	<description>Cutting edge security research as it happens.......</description>
	<lastBuildDate>Mon, 15 Mar 2010 10:26:50 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: mcgrimus</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-789852</link>
		<dc:creator>mcgrimus</dc:creator>
		<pubDate>Tue, 05 May 2009 12:46:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-789852</guid>
		<description>&quot;Windows Vista Vulnerable to StickyKeys Backdoor&quot;

Am I really the first one here to say, &quot;That&#039;s what she said!&quot; to this??</description>
		<content:encoded><![CDATA[<p>&#8220;Windows Vista Vulnerable to StickyKeys Backdoor&#8221;</p>
<p>Am I really the first one here to say, &#8220;That&#8217;s what she said!&#8221; to this??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Someone</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-787835</link>
		<dc:creator>Someone</dc:creator>
		<pubDate>Sat, 02 May 2009 06:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-787835</guid>
		<description>Works on 100% of campus computers.  Kind of scary the potential information someone nefarious can get.  Keylogger anyone?</description>
		<content:encoded><![CDATA[<p>Works on 100% of campus computers.  Kind of scary the potential information someone nefarious can get.  Keylogger anyone?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Windows Admin access via Sticky Keys &#124; Daniel (Moird) Myers</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-784992</link>
		<dc:creator>Windows Admin access via Sticky Keys &#124; Daniel (Moird) Myers</dc:creator>
		<pubDate>Mon, 27 Apr 2009 16:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-784992</guid>
		<description>[...] a really interesting hole in windows that has a variety of potential. I am going a bit off the original post with some added information. It seems though that a lot more people out there don&#8217;t see this [...]</description>
		<content:encoded><![CDATA[<p>[...] a really interesting hole in windows that has a variety of potential. I am going a bit off the original post with some added information. It seems though that a lot more people out there don&#8217;t see this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vista Vulnerabilities &#171; Brian Ladd&#8217;s Blog - Notes on Life</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-652859</link>
		<dc:creator>Vista Vulnerabilities &#171; Brian Ladd&#8217;s Blog - Notes on Life</dc:creator>
		<pubDate>Thu, 13 Nov 2008 15:13:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-652859</guid>
		<description>[...] Vista&#160;Vulnerabilities    http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-b... [...]</description>
		<content:encoded><![CDATA[<p>[...] Vista&nbsp;Vulnerabilities    <a href="http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-b.." rel="nofollow">http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-b..</a>. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MiniNoticias &#187; Blog Archive &#187; No tardes cuando vayas al baño</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-584352</link>
		<dc:creator>MiniNoticias &#187; Blog Archive &#187; No tardes cuando vayas al baño</dc:creator>
		<pubDate>Tue, 26 Aug 2008 20:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-584352</guid>
		<description>[...] en Windows Vista, como XP, 2000, y usando otras aplicaciones. Uno de estos ejemplos es el de las sticky keys, sethc.exe, comentado por uno de mis compañeros en nuestras listas. Al igual que la anterior, se [...]</description>
		<content:encoded><![CDATA[<p>[...] en Windows Vista, como XP, 2000, y usando otras aplicaciones. Uno de estos ejemplos es el de las sticky keys, sethc.exe, comentado por uno de mis compañeros en nuestras listas. Al igual que la anterior, se [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mervin</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-513596</link>
		<dc:creator>Mervin</dc:creator>
		<pubDate>Sun, 29 Jun 2008 18:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-513596</guid>
		<description>&quot;an attacker can use this method to bypass login on terminal servers and workstations with the remote desktop enabled. Since no third-party tools are being installed on the system and we are using Microsoft’s own files to achieve this, it will be difficult to detect for a typical administrator.&quot;

I just discovered couple of terminal servers in our university network where one could remote backdoor into using this Sticky-key backdoor method with full SYSTEM rights. So this technique is being used by bad guys and its shocking that M$ still don&#039;t protect sethc.exe and utilman.exe with windows file protection!!!</description>
		<content:encoded><![CDATA[<p>&#8220;an attacker can use this method to bypass login on terminal servers and workstations with the remote desktop enabled. Since no third-party tools are being installed on the system and we are using Microsoft’s own files to achieve this, it will be difficult to detect for a typical administrator.&#8221;</p>
<p>I just discovered couple of terminal servers in our university network where one could remote backdoor into using this Sticky-key backdoor method with full SYSTEM rights. So this technique is being used by bad guys and its shocking that M$ still don&#8217;t protect sethc.exe and utilman.exe with windows file protection!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-495139</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Sat, 14 Jun 2008 17:20:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-495139</guid>
		<description>Or, you could just turn off StickyKeys altogether. That would just about solve that problem.</description>
		<content:encoded><![CDATA[<p>Or, you could just turn off StickyKeys altogether. That would just about solve that problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rory</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-492146</link>
		<dc:creator>Rory</dc:creator>
		<pubDate>Wed, 11 Jun 2008 20:46:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-492146</guid>
		<description>WRONG!
You don&#039;t need admin access. Pop in Auditor or backdoor linux boots and in five minutes flat you can have the &#039;sploit in place and running.</description>
		<content:encoded><![CDATA[<p>WRONG!<br />
You don&#8217;t need admin access. Pop in Auditor or backdoor linux boots and in five minutes flat you can have the &#8217;sploit in place and running.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyrel &#8220;DotCom&#8221; Souza &#187; Lazy CMD prompt?</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-492096</link>
		<dc:creator>Tyrel &#8220;DotCom&#8221; Souza &#187; Lazy CMD prompt?</dc:creator>
		<pubDate>Wed, 11 Jun 2008 19:56:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-492096</guid>
		<description>[...] described in StickeyKeys Backdoor, you can swap sethc with cmd.exe and instead of stickey keys coming up when you hit shift five [...]</description>
		<content:encoded><![CDATA[<p>[...] described in StickeyKeys Backdoor, you can swap sethc with cmd.exe and instead of stickey keys coming up when you hit shift five [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GhaFear</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/12/windows-vista-vulnerable-to-stickykeys-backdoor/comment-page-1/#comment-471609</link>
		<dc:creator>GhaFear</dc:creator>
		<pubDate>Tue, 27 May 2008 16:12:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=218#comment-471609</guid>
		<description>I see a point, as far as the exe can&#039;t be replaced unless you have admin access.

But I have a problem with the login and loading a desktop. There should no way under any situation it being able to bypass it.

GhaFear</description>
		<content:encoded><![CDATA[<p>I see a point, as far as the exe can&#8217;t be replaced unless you have admin access.</p>
<p>But I have a problem with the login and loading a desktop. There should no way under any situation it being able to bypass it.</p>
<p>GhaFear</p>
]]></content:encoded>
	</item>
</channel>
</rss>
