<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx</link><description>No, no. For sure. I am not going to give you advise how to hack – but look at this video: http://www.offensive-security.com/movies/vistahack/vistahack.html . I am always amazed about these kind of videos, which still surprise people. If look years back,</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>   Hacking Windows Vista &amp;raquo; D' Technology Weblog: Technology, Blogging, Tips, Tricks, Computer, Hardware, Software, Tutorials, Internet, Web, Gadgets, Fashion, LifeStyle, Entertainment, News and more by Deepak Gupta.</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3061510</link><pubDate>Tue, 27 May 2008 10:46:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3061510</guid><dc:creator>   Hacking Windows Vista &amp;raquo; D' Technology Weblog: Technology, Blogging, Tips, Tricks, Computer, Hardware, Software, Tutorials, Internet, Web, Gadgets, Fashion, LifeStyle, Entertainment, News and more by Deepak Gupta.</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.ditii.com/2008/05/27/hacking-windows-vista/"&gt;http://www.ditii.com/2008/05/27/hacking-windows-vista/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3061569</link><pubDate>Tue, 27 May 2008 12:47:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3061569</guid><dc:creator>Stephen Spence</dc:creator><description>&lt;p&gt;This vector isn't new to Vista.&lt;/p&gt;
&lt;p&gt;As bitlocker isn't a standard feature it's not a universal fix for Vista either, only shipping on two of the Vista SKUs - Enterprise and Ultimate which represent a small proportion of the systems shipping with Vista.&lt;/p&gt;
</description></item><item><title>re: How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3062378</link><pubDate>Thu, 29 May 2008 05:29:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3062378</guid><dc:creator>stuart</dc:creator><description>&lt;p&gt;Surely this could be easily fixed by forcing Vista to check that the Utilman.exe file hasn't been tampered with? I still agree with you on Law #3, but it seems like this particular hack could be prevented.&lt;/p&gt;
</description></item><item><title>re: How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3062505</link><pubDate>Thu, 29 May 2008 11:22:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3062505</guid><dc:creator>rhalbh</dc:creator><description>&lt;p&gt;True, but this would prevent this single attack only. At the end of the day we need a way to completely protect software from being tampered, which would mean, having the trusted stack&lt;/p&gt;
&lt;p&gt;Roger&lt;/p&gt;
</description></item><item><title>re: How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3065137</link><pubDate>Tue, 03 Jun 2008 05:30:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3065137</guid><dc:creator>stuart</dc:creator><description>&lt;p&gt;I agree with you, Roger, but I think that any executable that can be launched prior to logging in could be checked to see if it has been tampered with. This would include utilman.exe as well as any other process that can launched under the system account before I've logged in.&lt;/p&gt;
</description></item><item><title>re: How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3065196</link><pubDate>Tue, 03 Jun 2008 09:00:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3065196</guid><dc:creator>rhalbh</dc:creator><description>&lt;p&gt;Valid point. This would add trust to the stack&lt;/p&gt;
&lt;p&gt;Roger&lt;/p&gt;
</description></item><item><title>re: How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3220994</link><pubDate>Wed, 01 Apr 2009 15:28:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3220994</guid><dc:creator>tyler</dc:creator><description>&lt;p&gt;that is a valid point i also agree with roger but also think that stuart is correct&lt;/p&gt;
</description></item><item><title>re: How to Hack Windows Vista</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/27/how-to-hack-windows-vista.aspx#3228864</link><pubDate>Tue, 21 Apr 2009 23:58:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3228864</guid><dc:creator>natxo</dc:creator><description>&lt;p&gt;This is also known to happen with the sticky keys program (sethc.exe); what blows my mind is: why o why do you allow this actions to take place *without* anyone logged on to the console of the OS? &lt;/p&gt;
&lt;p&gt;Of course I agree that having physical access to the system nearly gives you access to it, but why facilitate it? Why are these programs allowed to execute without logging in? That is just sloppy from MS, especially if one knows that this 'feature' has been present in all windows systems at least since windows 2000.&lt;/p&gt;
</description></item></channel></rss>