The Active Network
ActiveWin Anonymous | Create a User | Reviews | News | Forums | Advertise | VBA in Excel | Users Online: 0  
 

neowin.net

Amazon.com

  *  

  Windows Vista Vulnerable to StickyKeys Backdoor
Time: 01:00 EST/06:00 GMT | News Source: *Linked Within Post* | Posted By: Kenneth van Surksum

StickyKeys is an accessibility feature to aid handicapped users. It allows the user to press a modifier key, such as the Shift key, and have it remain active until another key is pressed. StickyKeys is activated by pressing the shift key or a modifier key five times in sequence and a beep is sounded. Sounds innocuous, right? Dead wrong!

Apparently, Windows Vista does not check the integrity of the file that launches StickyKeys “c:/windows/system32/sethc.exe” before executing it. Which means you could replace it with another executable and run it by depressing the shift key five times. A popular replacement is “cmd.exe.” After replacement, one could invoke this command prompt at the login prompt without the need to authenticate.

Read Only Comments
Return to News
  Displaying Comments 1 through 5 of 5
  This is an archived static copy of ActiveWin.com.
#1 By 6859 (206.156.242.36) at Tuesday, March 20, 2007 07:50:04 AM
I always knew I hated stickykeys for a reason, this is just another reason it is annoying.

#2 By 8556 (12.210.32.201) at Tuesday, March 20, 2007 08:32:36 AM
If I leave my car running, while I'm not in it, some low life can easily steal it. My car is vulnerable!

#3 By 9589 (71.71.37.109) at Tuesday, March 20, 2007 10:03:11 AM
Read the comments below this article, they skewer the author as a dufus. Hilarious!

#4 By 1401 (69.27.196.125) at Tuesday, March 20, 2007 11:47:48 AM
StickeyKeys Backdoor...That just sounds like fodder for endless dirty jokes... Butt I'll leave that one alone...

#5 By 65179 (221.128.180.152) at Wednesday, March 21, 2007 07:04:31 AM
Dunno about Vista, it must be the same, but in XP and earlier Windows versions at least, it is possible to keep StickyKeys enabled and disable ONLY the keyboard shortcut.



 

  *  
  *   *
 
replica watches