<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>"Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx</link><description>Expect to see more malware predating the patches - and how you can protect yourself. (Or, "Why you shouldn't run as admin, Part 2")</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#166054</link><pubDate>Fri, 25 Jun 2004 20:08:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:166054</guid><dc:creator>bilbo</dc:creator><description>why are they called &amp;quot;zero-day&amp;quot; attacks?&lt;br&gt;&lt;br&gt;just curious</description></item><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#166087</link><pubDate>Fri, 25 Jun 2004 20:33:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:166087</guid><dc:creator>Aaron Margosis</dc:creator><description>It refers to the number of days from public disclosure of the vulnerability to exploitation of the vulnerability.  &amp;quot;Zero-day&amp;quot; could be a malware author who manages to construct and launch a worm the same day that the patch came out, or that the discoverer launched an attack without publicly disclosing the vuln.&lt;br&gt;&lt;br&gt;Worm authors are getting faster, so it is becoming increasingly important to install patches quickly.  My contention is that we're going to be seeing more cases of the second variety.</description></item><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#166226</link><pubDate>Fri, 25 Jun 2004 22:34:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:166226</guid><dc:creator>Jeremy Foster</dc:creator><description>Your blog gave me an idea. If software development copanies like Microsoft gave more attention to individuals who privately revealed holes, then perhaps those attention-hungry hackers would choose the amiable way of capturing the public eye. They know they will get attention if they exploit the hole, but if they knew they would get attention if they revealed it responsibly, they may be more apt to.</description></item><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#166243</link><pubDate>Fri, 25 Jun 2004 22:55:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:166243</guid><dc:creator>Aaron Margosis</dc:creator><description>I agree completely, Jeremy.  In fact, this has already been Microsoft's policy for several years:&lt;br&gt;&lt;a target="_new" href="http://www.microsoft.com/technet/security/bulletin/policy.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/policy.mspx&lt;/a&gt;&lt;br&gt;</description></item><item><title>re: Why you shouldn't run as admin...</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#196501</link><pubDate>Mon, 26 Jul 2004 04:18:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:196501</guid><dc:creator>Aaron Margosis' WebLog</dc:creator><description /></item><item><title>Excellent LUA/non-admin resource</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#221798</link><pubDate>Sat, 28 Aug 2004 01:11:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:221798</guid><dc:creator>Franci Penov</dc:creator><description /></item><item><title>Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#409470</link><pubDate>Tue, 19 Apr 2005 03:22:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:409470</guid><dc:creator>Aaron Margosis' WebLog</dc:creator><description>Complete list of Aaron Margosis' non-admin / least privilege posts, for easy lookup.</description></item><item><title>Spread the LUA joy</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#427778</link><pubDate>Fri, 10 Jun 2005 19:12:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:427778</guid><dc:creator>tonyso</dc:creator><description>Get your friends and family, all those folks that come to you for computer help once their machines have...</description></item><item><title>A Beginning with LUA</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#450277</link><pubDate>Thu, 11 Aug 2005 08:22:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:450277</guid><dc:creator>Listen...You Smell Something?</dc:creator><description>About a year ago I was reading something (blog, article, billboard, I&lt;br&gt;don't know what) that was talking...</description></item><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#452844</link><pubDate>Thu, 18 Aug 2005 01:40:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:452844</guid><dc:creator>redxii</dc:creator><description>&amp;quot;But if the vulnerability is exploited through your web browser, email, IM, internet-connected game, etc., then the malicious code can do anything you can do.&amp;quot;&lt;br&gt;&lt;br&gt;I have seen the light, a limited account stopped, not mitigated damage of, the HTML Help exploit!</description></item><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#513632</link><pubDate>Tue, 17 Jan 2006 07:58:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:513632</guid><dc:creator>E-dave</dc:creator><description>Do programs like Prevx  do anything incompatible with virus protection software or firewalls?</description></item><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#567208</link><pubDate>Mon, 03 Apr 2006 14:48:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:567208</guid><dc:creator>Mike</dc:creator><description>It is possible on a ocmputer to make another administrator account. In doing this if one gets hacked into or w/e then you can get on your back up one that should have all your main games and programs on it and clean the other account or even delete with your passworded permission of course.</description></item><item><title>re: "Zero-day" attacks and using limited privilege</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#1353197</link><pubDate>Sat, 23 Dec 2006 22:43:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1353197</guid><dc:creator>Jake Tobash</dc:creator><description>&lt;p&gt;OK, this all sound very good. I like the idea of having users use LUA or FUS in order to run their web apps ONLY in LUA mode. Then, they can switch back to admin for all the regular apps (OFFLINE only allowed at my co.) without any sort of restrictions on the SW. Many web apps have no sort of full Windows compatiblity (BAD programming), so I just tell them &amp;quot;If it accesses the net at all, it must be run in LUA mode). So far, everything has worked out.&lt;/p&gt;
</description></item><item><title>Table of Contents (Aaron Margosis' Non-Admin WebLog)</title><link>http://blogs.msdn.com/aaron_margosis/archive/2004/06/25/166039.aspx#4915191</link><pubDate>Fri, 14 Sep 2007 21:06:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4915191</guid><dc:creator>Aaron Margosis' "Non-Admin" WebLog</dc:creator><description>&lt;p&gt;Table of Contents - blog posts on Aaron Margosis' Non-Admin WebLog&lt;/p&gt;
</description></item></channel></rss>