ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Malicious code 'could hide in Windows Registry'

Joris Evers CNET News.com

Published: 30 Aug 2005 09:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Miscreants could hide their malicious software on a Windows PC by using overly long registry keys, security experts have warned.

These keys are stored in the Windows Registry, a core part of the operating system that stores PC settings. Some antivirus and anti-spyware products scan the registry for malicious programs, but this new weakness allows hackers to hide the presence of their applications, according to security vendor StillSecure.

"It can be used to hide malicious programs on a system that would go undetected by security software or registry scanning tools," said Mitchell Ashley, chief technology officer at StillSecure, which is based in Louisville, Colo. Detection and cleanup could be difficult to impossible, according to StillSecure.

The SANS Internet Storm Center, which tracks Internet threats, on Thursday listed some applications that, according to reports it received, can be tricked by the longer registry keys. The list includes AdAware, Microsoft's Windows AntiSpyware, HijackThis, Norton SystemWorks 2003 Pro, Microsoft's Windows Registry Editor and WinDoctor.

"It is important for users to know if they may have a blind spot in their local system security," SANS associate Robert Danford wrote on the SANS ISC Web site. "The [essential information] here is that... it will be important to many to watch for product updates in the coming weeks." Danford also works for the security alert team at StillSecure.

Of most concern are the so-called "run" keys in the registry. These keys are used to start applications when a Windows PC boots. Microsoft's Registry Editor and several popular security programs won't detect the overly long entries in the Windows Registry, yet the applications will still start, according to StillSecure's Ashley.

"It would be very easy for a spyware programmer to hide a keystroke logger on your machine using this technique," Ashley said.

Microsoft is investigating the issue, a company representative said in a statement emailed on Friday. The software maker notes that an attacker can't hide anything without first breaking into a system.

"This issue could not allow an attacker to remotely or locally attack a user's computer," the Microsoft representative said. "Rather, the attacker would already have to have compromised the computer or convinced the computer user to run malicious software."

According to Microsoft, the issue is not a security vulnerability, but a function within the operating system that could be misused. Microsoft said it is not aware of the trick being employed to hide software.

However, SANS on Thursday said it started to see "some possible reports of malware which utilizes this concealment technique." The organisation said it expects to see that continue over the next few weeks as software makers fix their products to allow these keys to be visible.

Security monitoring company Secunia rates the Windows Registry issue "not critical". The French Security Incident Response Team also labels it "low risk".

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
72 out of 126 people found this useful



Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Web Developer, CSS, HTML, East Yorkshire

The main responsibilities will be the administration and support of web-based programs, including internal web applications, external websites and ...

Java Developer - Reading - 35-40,000

Create and amend programs in accordance with the design to meet the Statement of Requirements (SOR). Plans to ensure programs are error free. We are ...

ICT Developer East Yorkshire Immediate

You will be working on the department that manages the company's global web programs. You will be responsible for the administration and support of ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment