Earlier quoted context omitted.
reddit, imgur, news sites. It was via an ad delivered over an ad network, so who knows really.
How come the adblocker didn't block the ad network?
Symantec found evidence of Longhorn against 40 targets spread in 16 countries
41–49 of 49 posts
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#42Too bad it's not like Microsoft's Longhorn - then it would have been delivered years late as a shadow of it's promised self (Vista) ;)
Yeah, when I read the headline I was puzzled. "What has a canned MS project got to do with Symantec?" God I'm so old.
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#43Earlier quoted context omitted.
- Don't run day to day with local admin
Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#44>On one occasion a computer in the United States was compromised but, following infection, an uninstaller was launched within hours, which may indicate this victim was infected unintentionally. How do they know that?
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#45Earlier quoted context omitted.
Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people
Well, I think this picture sums up a lot of thoughts on this subject: https://xkcd.com/1200/ In a nutshell, your user account has all your data, all your session cookies, all your logins and passwords, all your documents.... Everything. And what can root/Administrator do? That's right, play with device drivers and systems stuffs. Once you have the primary user's account, unless it's a multiuser system, it's game over…
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#46Earlier quoted context omitted.
Well, I think this picture sums up a lot of thoughts on this subject: https://xkcd.com/1200/ In a nutshell, your user account has all your data, all your session cookies, all your logins and passwords, all your documents.... Everything. And what can root/Administrator do? That's right, play with device drivers and systems stuffs. Once you have the primary user's account, unless it's a multiuser system, it's game over…
Lack of root makes being stealthy and covering tracks more difficult. Log clearing almost always requires elevation. If getting owned is a given (and it is) then the most important thing is detection after the fact.
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#47Earlier quoted context omitted.
Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people
That's because UAC in windows is worthless, it's a broken version of sudo that fails to do the one thing necessary, force a re-authentication of credentials. There's little point in popping up a warning than people can simply click right past without requiring admin credentials.
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#48Earlier quoted context omitted.
That's because UAC in windows is worthless, it's a broken version of sudo that fails to do the one thing necessary, force a re-authentication of credentials. There's little point in popping up a warning than people can simply click right past without requiring admin credentials.
sudo as root usually doesn't ask for password either.
Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries
#49Earlier quoted context omitted.
That's because UAC in windows is worthless, it's a broken version of sudo that fails to do the one thing necessary, force a re-authentication of credentials. There's little point in popping up a warning than people can simply click right past without requiring admin credentials.
It works if you have a separate admin account. Then at least you have to enter its credentials, if not your own.