Microsoft Says, Don't Press the F1 Key In XP
Ian Lamont writes "Microsoft has issued a security advisory warning users not to press the F1 key in Windows XP, owing to an unpatched bug in VBScript discovered by Polish researcher Maurycy Prodeus. The security advisory says that the vulnerability relates to the way VBScript interacts with Windows Help files when using Internet Explorer, and could be triggered by a user pressing the F1 key after visiting a malicious Web site using a specially crafted dialog box."
As long as CTRL-ALT-DELETE still works we're golden.
F1rst
F1!
I need somebody!
F1!
Not just anybody!
F1!
You know I need someone!
F1!
I find the idea that Microsoft is angry at the people who found a problem in Microsoft software not telling Microsoft about it hilarious.
"Maybe this world is another planet's hell"
Aldous Huxley
How about we tax microsoft for their polluting the internet with their insecure-by-design OS installs? About $50 per install will put a dent in all the economic damage Windows causes.
Don't press the F1 key? Jesus fucking christ. What next, don't power up the box?
Remain calm! All is well!
This won't affect anybody: those users that aren't very computer literate don't even know that help exists and is one key away... the other ones already know that windows help won't lead you anywhere!
"Microsoft is concerned that this new report of a vulnerability was not responsibly disclosed, potentially putting computer users at risk. We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed."
Call me a cynic, but I've got to be honest: The net effect may be positive, but I don't believe that Microsoft's idea of 'responsible disclosure' results in high priority investigation and timely patching of MS products.
This is yet another reason why MS' idea of a tax to deal with malware tax is stupid.
It's almost amusing that a Web browser is so tightly integrated with the operating system that scripts run by it can influence core system functions without actually rooting the machine. I guess this is what happens when you ignore decades of computer security history and discard the principle of least-privilege. Hopefully Windows 7 (and Vista) is not defective enough to allow a userspace application to screw around with a built-in OS function like help files.
Look, if we're honest, the only reason why IE is so tightly integrated with the OS in the first place is because Microsoft wanted to abuse its desktop OS monopoly by using it to dominate the browser market. If not for that, IE would be a standalone browser and would be separate from any built-in HTML rendering that's part of the core Windows system, like help files in this case. This is one reason why I use Linux: Microsoft obviously cares about its marketshare more than my security, and I cannot in good conscience use my money to support a company with such backwards priorities. I'm sure someone will chime in with talk about how useful Windows is, and I won't argue (much) with that.
This is really a moral issue. Anyone with decent principles wouldn't want to reward a company with such questionable business practices, not even if they made the finest software available. I'm sure the rest of you who don't have such principles will have a million excuses for why you continue to support Microsoft with your wallets, and that's fine. Every dishonest organization has its useful idiots without which it could not continue existing.
I tried it and got a Firefox friendly help tab. F1 is the second most annoying key.
What you really don't want to press is that cursed, evil POWER key. You know, when you're trying to find the Page Up ke
Given the quality of the F1-contents these days, especially in MS apps, that's not such a bad advice - google instead.
This is ucking ridiculous. I'm a ullerene chemist, or uck's sake!
press F1 to continue.
This probably affects any help file in html format, which is displayed through the IE rendering engine. Many new applications use html help files.
We're sunk! What happens someone finally figures out the space bar hack?
Can I change another key to be the any key? I can never find that darn thing.
AutoHotkey has its own free editor with syntax highlighting.
.EXE files.
I just checked. My AutoHotkey script is 1,639 lines, 52,140 bytes. That doesn't include the special scripts.
The source code is available, as is a GUI creator.
The AutoHotkey programming language is quirky.
AutoIt has a more standard language. AutoIt is better for complex automated installation scripts, for example. AutoHotkey is better for hotkeys. Both offer compilation of their scripts to
You do realize that KDE, for example, also uses the same HTML component - KHTML - for both its standalone browser, and help system (and many other things)? I'd expect OS X to do the same with WebKit. Gnome is different, but mainly because of the mess they made with GtkHTML vs Gecko vs WebKit; the long-term plan, as I understand, is still to migrate to WebKit for everything.
It's also purely a matter of practicality - I mean, why would you have two distinct HTML renderers?
Needless to say, I turned down the job offer. It doesn't surprise me how they keep making flub ups like this when the people at their company are so arrogant.
I don't see what the big deal is. Windows is a perfectly secure operating system as long as you don't access any external media or connect to the internet.
(Coming from someone who just spent 10 hours removing the Internet Security 2010 trojan malware from his wife's computer.)
Take off every Sig. For great justice.
The same HTML rendering component I can understand, but in this case it appears a script running in a web browser instance of the component can somehow affect the help rendering instance, and that is a quality WTF.
Come as you are, do what you must, be who you will.
I never hit F1. I've found windows help to be absolutely useless.
You do realise that KDE and Gnome are not operating systems? "OS X" is also not an operating system in the typical sense of the word; it has Darwin [wikipedia.org] under the covers, responsible for managing all the hardware and important functions like permissions, ensuring that the core system can't be hosed when an rogue application is somehow allowed to be run as a user.
Guess what? Windows works in exact same way. There's the kernel there, then a set of userland APIs on top of then, then the UI layer, and finally the actual DE. Just because they are shipped in a single box, and aren't explicitly marked as separate, and given funny-sounding names, doesn't mean they aren't there.
Do you seriously think that NT kernel somehow uses IE under covers?
It is comforting to know that if something goes wrong on Linux or OS X (or similar), that the problem is almost always limited to only a single 'user' account
It depends on your definition of "something goes wrong". A privilege escalation exploit has the same problems on any OS, and without one you can't break the system on modern Windows versions (speaking of which, note how Vista/7 aren't vulnerable in this case), either - user account security is not fundamentally different in NT compared to Unix.
Oh, and this isn't what is usually understood by a privilege escalation vulnerability - it doesn't give you root or anything. It's rather a sandbox breakage - scripts which should be executing in a browser sandbox "leak out", and run with all privileges of the user interacting with the machine.
Especially with XP, the last version of Windows that allows you to nuke absolutely every service, disabling help is one of the first things I do.
I scream. You scream. I assume that means we're both acquainted with the problem. We proceed.
You're welcome.
Best way to stay trouble free on Windows? Don't use IE. Or Outlook. Or IIS.
150 Opening BINARY mode data connection for slashdot.sig (129323052 bytes).
If you are still using XP at this point, who cares? Go for it. Press F1 while running FlashPlayer and Acrobat and IE6 simultaneously. If you gave a shit or had any data worth protecting you'd already be using a Mac or other Unix.