January 19th, 2009
AutoPlay - Fun and social engineering
This is something that Microsoft needs to fix in Windows 7.
Downadup’s autorun.inf file uses an action keyword and icon extracted from shell32.dll to produce the following:
The category is “Install or run program” but the text and icon are for “Open folder to view files“.
The first option will run Downadup, not good. The second “general” option is the choice that will safely open the USB drive.
Being curious, we tried this autorun.inf with Windows 7:
And the results for Windows 7 were the same as Vista’s.
It really shouldn’t be that easy to game the AutoPlay feature. Microsoft needs to fix this.
Adrian is a technology journalist and author who has devoted over a decade to helping users get the most from technology. He also runs a popular blog called The PC Doctor. See his full profile and disclosure of his industry affiliations
Want to get in touch? Got a tip? Feel free to drop me a note! I ALWAYS respect anonymity. I'm also on Twitter (@the_pc_doc)
Right to Reply: Should any industry representatives wish to comment on any posts on Hardware 2.0, I will be happy to publish their reply verbatim on this blog.
Subscribe to Hardware 2.0 via Email alerts or RSS.











