<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1153007634360357466</id><updated>2011-04-21T15:42:02.532-07:00</updated><category term='govindgsr Computers Vista Microsoft Vista Architecture Compromised Busted Govind Singh govindgsr'/><title type='text'>Govind's Blog</title><subtitle type='html'>This article tells how the security and architecture of the most secure OS(i.e. MS-VISTA) from Microsoft could be busted by taking the advantages of serious flaws present in it.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://govindgsr.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1153007634360357466/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://govindgsr.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Govind Singh</name><uri>http://www.blogger.com/profile/11088087126879990209</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1153007634360357466.post-8447746171968500544</id><published>2007-11-26T23:17:00.000-08:00</published><updated>2007-12-06T01:22:27.253-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='govindgsr Computers Vista Microsoft Vista Architecture Compromised Busted Govind Singh govindgsr'/><title type='text'>Vista Architecture Compromised &amp; Busted..</title><content type='html'>&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Hi Guys, &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;This article is about some serious problems with Microsoft VISTA operating system. Though VISTA claims to be the most secure operating system amongst the Microsoft OS family, still there are serious flaws which Compromise, Collapse &amp;amp; Bust down the Microsoft VISTA Security and Architecture.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Right now I will talk about some Unbelievable &amp;amp; Theoretically impossible but practically possible aspects of Vista which simply violates the Vista Architecture. I will tell you about 9 serious Violations punching down the holes across the whole Vista Architecture thereby bursting it. They include :&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(1) Logging into the system bypassing all the Windows logon sequences(CTRL+ALT+DEL)...by &lt;/span&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;taking advantage of flaw present in "Run as Admin" Option. .&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(2) User with Dual Identity. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(3) Invisible Ghost Super User.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(4) Two users Logged in Same Session.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(5) Multiple Users Logged in Simultaneously on a Standalone system.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(6) Dual sign-on of a User(User Logging in Twice without Logoff/Shutdown). &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(7) User with Dual set of Privileges.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(8) UAC shutdown without any change in security policies.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(9) Dual UAC behavior. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Want to Skip the article and go to video directly to check it live then click the link below:&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;a href="http://www.youtube.com/watch?v=fRCx_Yovj4U"&gt;http://www.youtube.com/watch?v=fRCx_Yovj4U&lt;/a&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Before starting let me ask a couple of questions. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(1) Everyone knows the utility of "Run As Admin." Option(it simply runs a application/process in context of Admin)but if I ask you that, Is it possible to login to a system using "Run As Administrator" Option ?.. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;--------Probably the answer would be: No its not possible at all. To login to system there are proper sequence/steps as per the OS Architecture.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="color:#3333ff;"&gt;Watch the video, "Run as Admin" instead of running the application in context of admin allows me to login that user in a invisible mode(not known to OS) with system privileges (privileges above than admin) bypassing all the Windows logon sequences &amp;amp; that too within the same session &amp;amp; that too in a standalone system.&lt;/span&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(2) Can a User have a dual identity?.. (Say for Eg. There are 3 users A,B &amp;amp;C. Now i mean to ask that Can a User "A" act as A &amp;amp; B as well?)&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;--------Probably the answer would be: You are talking against the Architecture/Principles of Windows OS. There is no such concept of dual identity in windows. Each user has got its own separate identity, privileges ..etc.. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(3) Now if i ask, Can a user be Logged in a Invisible Mode ?..&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;--------Probably the answer would be: What is Invisible mode .There is no such concept in Windows Vista .You are talking the things Practically impossible and totally against Vista Architecture.(Well, Invisible mode is a mode in which user is signed in without any notification/Knowledge to other parts of OS. In other words we can say "Invisible mode is a mode in which user is signed in but not signed in for OS.") &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(4) Can two users A &amp;amp; B , be Logged into one session?..&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;-------Probably the answer would be: Its against the Windows system architecture. Each user has got its own session etc.... &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(5) Is it possible that 2 users or multiple users can be logged in at once simultaneously and working together in a Standalone System at a time ?..&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;-------The most probable answer would be: Since its a Standalone system .The VISTA-OS architecture says only one user at a time can be logged in. The max possibility is that you can run a program in context of another user &amp;amp; that's it. You cannot have 2 users logged in simultaneously &amp;amp; working together. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(6) Can a User Login Twice ?..(I mean Say user A is logged in. He never log off nor he comes out by pressing Ctrl+Alt+Del or switch user or by any shortcut key. Then is it possible for User A to login Once again.)&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;-------Probably the answer would be: No its not possible at all &amp;amp; its strictly against the OS architecture. Once a user is logged in then he has to come out by Logoff/Shutdown from the account then only he can login again. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(7) Can a User have a dual set of Privileges.(For Eg. Can a User "A" have a set of Administrative Privileges and set of System Privileges both at a time)&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;-------Probably the answer would be: You are talking the things Practically impossible and totally against the OS Architecture. Each User in a system have a unique ID and unique set of Privileges. Its not possible for a user to have the Privileges of 2 accounts at a time. if the User A is Administrator then he will have Only &amp;amp; Only Admin Privileges throughout. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q8) Is it possible to shut down UAC permanently without editing the Local security Policy or anything ...?&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;-------The most probable answer would be: No.... its not possible to disable UAC without editing it from control panel/Local security Policy .You can edit the Local security Policy &amp;amp; i will be redirected to some link saying Login as Admin then run secpol.msc then edit the setting "Behavior elevation prompt for administrator" or "Run all administrators in Admin Approval Mode". Now Restart you computer ...etc. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:Arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;Q(9) Is it possible that UAC can have a dual behavior for a same user ?..(I mean to say is it possible that UAC behaves differently for the same user "A",some time UAC gets enabled &amp;amp; sometime it won't automatically )&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;-------The most probable answer would be: No, its not at all possible because if a application is invoked using Run as Admin then Svchost.exe launches consent.exe.....etc then UAC pops Up and UAC is confined within the system boundaries and its behavior is consistent across the User. &lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;span style="color:#3333ff;"&gt;&lt;span style="font-family:arial;"&gt;I guess that everyone will agree with the fact that all the above discussed 9 questions are the architectural principles of Windows VISTA Operating system.Its very hard to believe if i say that all the above said 9 architectural principles of Windows VISTA Operating system can be breached &amp;amp; violated.Well, taking advantages of the Serious Flaws present in Microsoft VISTA, A sample application named "VistaOSViolation.exe" (written for educational purpose) is breaching &amp;amp; violating the above discussed 9 architectural principles of Microsoft VISTA.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;VistaOSViolation.exe does the following jobs:&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;(1) It logs-in a User through Run As Administrator option.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(2) It forces a User to have Dual Identity.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(3) It logs-in a User in the Invisible mode. (The remarkable aspect about this Invisible User is that , Its a Super User which is logged in silently within the Standard(Limited) User account and almost every security Feature/Policy of VISTA FAILS to get applied here. This Invisible Ghost User has got the Full Unrestricted access to the whole System. It can perform any operation without any barrier(i.e.Neither UAC pops up nor anything stopping it) and without any notification to the operating system.)&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(4) It logs-in a 2 Users in one session. More than 2 users can also be Logged-in into the same session.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(5) It forces 2 users login &amp;amp; working together in a Standalone System at a time. More than 2 users can also be Logged-in a Standalone System.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(6) It compels dual Sign-on of a User.(User Login-in twice without Logoff/shutdown etc..)&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(7) It compels the Same User to have a dual set of privileges.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(8) It forces permanently Shut-down of UAC without editing/changing the security/system policies.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;(9) It forces the UAC to have a dual behavior.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;span style="color:#3333ff;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;VistaOSViolation.exe does all the above said tasks without installing/invoking any kind of device-driver or Rootkit.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="color:#3333ff;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Well, not able to trust what &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#3333ff;"&gt;you read above then kindly check the video at Youtube(link given below) showing how VistaOSViolation.exe is breaching &amp;amp; violating all the above discussed architectural principles of Microsoft VISTA.&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=fRCx_Yovj4U"&gt;http://www.youtube.com/watch?v=fRCx_Yovj4U&lt;/a&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;script language="JavaScript" src="http://www.blogcatalog.com/rate-button.js.php?id=4334330" type="text/javascript"&gt;&lt;/script&gt;&lt;br /&gt;&lt;noscript&gt;&lt;/noscript&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1153007634360357466-8447746171968500544?l=govindgsr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://govindgsr.blogspot.com/feeds/8447746171968500544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1153007634360357466&amp;postID=8447746171968500544' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1153007634360357466/posts/default/8447746171968500544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1153007634360357466/posts/default/8447746171968500544'/><link rel='alternate' type='text/html' href='http://govindgsr.blogspot.com/2007/11/vista-architecture-compromised-busted.html' title='Vista Architecture Compromised &amp; Busted..'/><author><name>Govind Singh</name><uri>http://www.blogger.com/profile/11088087126879990209</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry></feed>
