Live data from Hacker News

RedSun: System user access on Win 11/10 and Server with the April 2026 Update

github.com

31–40 of 67 posts

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#31
post #27
post #20

I remember the times when Microsoft had a lot of problems 20 years ago because of Sasser and other viruses that were taking over Windows. They did not have any contenders. Yet they have stopped any software development for 9 months just to re-work their entire codebase to prevent things like direct memory execution and stuff like that. The result of that was Windows XP Service Pack 2. After that thing windows XP beca…

I don't think SP2 made much of a difference in the popularity of XP. It was already dominant, and it's mostly remembered as "legendary" because it had become the target platform for every hardware and software vendor on the planet. Windows 98 was too flaky to engender any serious friction to upgrades, and Windows 2000 was not consumer-friendly enough; XP effectively unified the consumer and professional desktop marke…

It was not that bad. I remember when SP fixed a bunch of issues with bluetooth, and windows CD burning program was better than any of the Nero Burning ROMs, cause those became unusable overbloated.

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#32
post #29
post #23

Earlier quoted context omitted.

> Windows XP Service Pack 2. After that thing windows XP became a legend. God that was an era. XP SP2 was a great OS, IE was the best browser, MSN was the most popular messenger, Skype was acquired, HTC's Windows CE devices were shipping real web browsers that worked over 3G. By the end of the Ballmer era, Microsoft has lost the OS, the browser, the messenger, the meeting service and mobile.

I agree with you on everything except the browser. I'm pretty sure I was using Firefox (or maybe Opera?) on Windows before the release of Vista. I know I was still using IE for some ActiveX web apps for a while. This was the era that I switched over to Linux full-time, but both Windows 2000 and XP were great OSes at this time. Linux was painful to adopt, but I really loved the promise of "full-control" over my comput…

https://gs.statcounter.com/browser-market-share#monthly-2009...

Yes, I've just checked, even in 2009 you still have IE over 64% of browser usage.

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#33

helpfully the user provides a second tool which automatically turns off Windows Defender so you can't be affected by this: https://github.com/Nightmare-Eclipse/UnDefend

> It runs in two modes, passive and aggressive

Lol

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#34
post #28

Earlier quoted context omitted.

That's how the exploit works.

I can't seem to find any system files replaced, and the .exe was never executed. I'm running this in a test VM, but from what I can see, Defender signatures have been updated to block this prior to execution. The exploit, from my reading, needs to be executed in order to do it's thing, but Defender isn't allowing it to be written to the filesystem on download.

What is Defender marking it as? I also wonder if they are just special casing this program and it would work again if the code was shuffled a bit or if it used the AMSI sig [0] instead of EICAR or if they actually fixed the problem.

[0] https://github.com/Roadmvn/C-Full-Offensive-Course/blob/main...

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#36
post #20

I remember the times when Microsoft had a lot of problems 20 years ago because of Sasser and other viruses that were taking over Windows. They did not have any contenders. Yet they have stopped any software development for 9 months just to re-work their entire codebase to prevent things like direct memory execution and stuff like that. The result of that was Windows XP Service Pack 2. After that thing windows XP beca…

There were several points in time (after the SP2 too) when installing WinXP with an active internet connection was nearly impossible, because it would get infected during the installation and shut itself down halfway through it.

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#37
post #27
post #20

I remember the times when Microsoft had a lot of problems 20 years ago because of Sasser and other viruses that were taking over Windows. They did not have any contenders. Yet they have stopped any software development for 9 months just to re-work their entire codebase to prevent things like direct memory execution and stuff like that. The result of that was Windows XP Service Pack 2. After that thing windows XP beca…

I don't think SP2 made much of a difference in the popularity of XP. It was already dominant, and it's mostly remembered as "legendary" because it had become the target platform for every hardware and software vendor on the planet. Windows 98 was too flaky to engender any serious friction to upgrades, and Windows 2000 was not consumer-friendly enough; XP effectively unified the consumer and professional desktop marke…

Also, technically XP was Windows NT 5.1, so it was built on a solid basis.

Whereas 98 was still in the kinda DOS-based 9x line.

And I fully agree with you to not mention Windows Me.

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#38
post #28

Earlier quoted context omitted.

I can't seem to find any system files replaced, and the .exe was never executed. I'm running this in a test VM, but from what I can see, Defender signatures have been updated to block this prior to execution. The exploit, from my reading, needs to be executed in order to do it's thing, but Defender isn't allowing it to be written to the filesystem on download.

What is Defender marking it as? I also wonder if they are just special casing this program and it would work again if the code was shuffled a bit or if it used the AMSI sig [0] instead of EICAR or if they actually fixed the problem. [0] https://github.com/Roadmvn/C-Full-Offensive-Course/blob/main...

Detected: Program:Win32/Wacapew.C!ml

With a link to: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#39
post #32
post #29

Earlier quoted context omitted.

I agree with you on everything except the browser. I'm pretty sure I was using Firefox (or maybe Opera?) on Windows before the release of Vista. I know I was still using IE for some ActiveX web apps for a while. This was the era that I switched over to Linux full-time, but both Windows 2000 and XP were great OSes at this time. Linux was painful to adopt, but I really loved the promise of "full-control" over my comput…

https://gs.statcounter.com/browser-market-share#monthly-2009... Yes, I've just checked, even in 2009 you still have IE over 64% of browser usage.

They said IE was the best browser, not the most popular. I wouldn't dispute that IE was more commonly used at the time.

Just checked your link and this fits with what I thought in terms of marketshare. You can see that Firefox was ~25% of marketshare in 2009. Which is an enormous share of the pie when you consider that they couldn't stick a download link on the front page of the most dominant search engine, and it didn't come preinstalled.

Never used Maxthon.

Damn, this also reminded me that RSS feeds were everywhere back then, and the browser supported it directly.

Re: RedSun: System user access on Win 11/10 and Server with the April 2026 Update

#40
post #13

Earlier quoted context omitted.

Only if you’re running daemons as root. Which would be an idiotic move to begin with because that’s not how distros package their services. So you’d have to intentionally make this mistake.

Intentionally? Ignorance is bliss! Simply use docker in its (old) default setup, instead of podman, apptainer, docker-rootless ... and that world is yours. Added bonuses are the incredible stupid integration with ufw on Ubuntu, images with laughable uid mapping, ... How that shit got traction baffles me.

That’s just the docker daemon. The actual docker services would (or at least should) still be running as its own user/group just like they would if you were running them on the host.

And that’s exactly how any reputable image would be built.

Post reply on HN