mastodon.ie is one of the many independent Mastodon servers you can use to participate in the fediverse.
Irish Mastodon - run from Ireland, we welcome all who respect the community rules and members.

Administered by:

Server stats:

1.6K
active users

#microsoftwindows

3 posts3 participants0 posts today
Pyrzout :vm:<p>Forensic journey: Breaking down the UserAssist artifact structure – Source: securelist.com <a href="https://ciso2ciso.com/forensic-journey-breaking-down-the-userassist-artifact-structure-source-securelist-com/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ciso2ciso.com/forensic-journey</span><span class="invisible">-breaking-down-the-userassist-artifact-structure-source-securelist-com/</span></a> <a href="https://social.skynetcloud.site/tags/rssfeedpostgeneratorecho" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rssfeedpostgeneratorecho</span></a> <a href="https://social.skynetcloud.site/tags/CyberSecurityNews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurityNews</span></a> <a href="https://social.skynetcloud.site/tags/Digitalforensics" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Digitalforensics</span></a> <a href="https://social.skynetcloud.site/tags/IncidentResponse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IncidentResponse</span></a> <a href="https://social.skynetcloud.site/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://social.skynetcloud.site/tags/Researcherstools" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Researcherstools</span></a> <a href="https://social.skynetcloud.site/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/securelistcom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securelistcom</span></a> <a href="https://social.skynetcloud.site/tags/threathunting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>threathunting</span></a> <a href="https://social.skynetcloud.site/tags/TIandIRposts" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TIandIRposts</span></a> <a href="https://social.skynetcloud.site/tags/research" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>research</span></a> <a href="https://social.skynetcloud.site/tags/SOC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOC</span></a></p>
Jérôme Herbinet | FLOSS<p>♥️ Merci <a href="https://pouet.chapril.org/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> pour tous ces efforts que vous déployez sans relâche depuis tant d'années pour me faire détester <a href="https://pouet.chapril.org/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> (et <a href="https://pouet.chapril.org/tags/MicrosoftOffice" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftOffice</span></a>, soit dit en passant) et aimer profondément GNU/Linux et les <a href="https://pouet.chapril.org/tags/LogicielsLibres" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LogicielsLibres</span></a> en général. Franchement, bravo et merci ! Continuez comme ça 👏 </p><p>🔗 <a href="https://www.linkedin.com/posts/cedric-delberghe_windows11-sobriaeztaez-dsi-activity-7348584195327160321-G2Hl?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAnvbn0BKgVWNiI-qXVKW2yp0P6EwiUZ8Aw" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">linkedin.com/posts/cedric-delb</span><span class="invisible">erghe_windows11-sobriaeztaez-dsi-activity-7348584195327160321-G2Hl?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAnvbn0BKgVWNiI-qXVKW2yp0P6EwiUZ8Aw</span></a></p><p>#️⃣ <a href="https://pouet.chapril.org/tags/GAFAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GAFAM</span></a> <a href="https://pouet.chapril.org/tags/Windows10" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows10</span></a> <a href="https://pouet.chapril.org/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> <a href="https://pouet.chapril.org/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://pouet.chapril.org/tags/FreeSoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FreeSoftware</span></a> <a href="https://pouet.chapril.org/tags/FOSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FOSS</span></a> <a href="https://pouet.chapril.org/tags/FLOSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FLOSS</span></a> <a href="https://pouet.chapril.org/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://pouet.chapril.org/tags/BigTech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BigTech</span></a> <a href="https://pouet.chapril.org/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://pouet.chapril.org/tags/Windaube" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windaube</span></a></p>
Aptivi<p>Microsoft outs the July 2025 security patch for Windows 11!</p><p><a href="https://mastodon.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://mastodon.social/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://mastodon.social/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodon.social/tags/Computers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Computers</span></a> <a href="https://mastodon.social/tags/Laptops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Laptops</span></a> <a href="https://mastodon.social/tags/TechNews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechNews</span></a> <a href="https://mastodon.social/tags/TechUpdates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechUpdates</span></a></p><p><a href="https://officialaptivi.wordpress.com/2025/07/09/windows-11-july-2025-patch-is-out/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">officialaptivi.wordpress.com/2</span><span class="invisible">025/07/09/windows-11-july-2025-patch-is-out/</span></a></p>
JdeBP<p><span class="h-card" translate="no"><a href="https://framapiaf.org/@pmevzek" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>pmevzek</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@Edent" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Edent</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@rmbolger" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rmbolger</span></a></span> </p><p>You are bearing this news a quarter of a century behind Daniel J. Bernstein, you should know. (-:</p><p><a href="https://mastodonapp.uk/tags/djbdns" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>djbdns</span></a> <a href="https://mastodonapp.uk/tags/DNS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DNS</span></a> <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a></p>
JdeBP<p><span class="h-card" translate="no"><a href="https://framapiaf.org/@pmevzek" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>pmevzek</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@Edent" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Edent</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@rmbolger" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rmbolger</span></a></span> </p><p>nslookup isn't deprecated on Windows, which is what we're talking about here.</p><p><a href="https://learn.microsoft.com/en-gb/windows-server/administration/windows-commands/nslookup" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">learn.microsoft.com/en-gb/wind</span><span class="invisible">ows-server/administration/windows-commands/nslookup</span></a></p><p>Good luck finding a dig for Windows. I'm still pointing people to William Stacey's netdig, I notice. I should probably fix that, since it vanished over a decade ago, which is a shame.</p><p><a href="https://jdebp.uk/FGA/dns-diagnosis-tools.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">jdebp.uk/FGA/dns-diagnosis-too</span><span class="invisible">ls.html</span></a></p><p><a href="https://mastodonapp.uk/tags/nslookup" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nslookup</span></a> <a href="https://mastodonapp.uk/tags/DNS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DNS</span></a> <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a></p>
Pyrzout :vm:<p>Batavia spyware steals data from Russian organizations – Source: securelist.com <a href="https://ciso2ciso.com/batavia-spyware-steals-data-from-russian-organizations-source-securelist-com/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ciso2ciso.com/batavia-spyware-</span><span class="invisible">steals-data-from-russian-organizations-source-securelist-com/</span></a> <a href="https://social.skynetcloud.site/tags/rssfeedpostgeneratorecho" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rssfeedpostgeneratorecho</span></a> <a href="https://social.skynetcloud.site/tags/MalwareDescriptions" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MalwareDescriptions</span></a> <a href="https://social.skynetcloud.site/tags/MalwareTechnologies" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MalwareTechnologies</span></a> <a href="https://social.skynetcloud.site/tags/CyberSecurityNews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurityNews</span></a> <a href="https://social.skynetcloud.site/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://social.skynetcloud.site/tags/Targetedattacks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Targetedattacks</span></a> <a href="https://social.skynetcloud.site/tags/Windowsmalware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windowsmalware</span></a> <a href="https://social.skynetcloud.site/tags/securelistcom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securelistcom</span></a> <a href="https://social.skynetcloud.site/tags/spearphishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>spearphishing</span></a> <a href="https://social.skynetcloud.site/tags/PowerShell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerShell</span></a> <a href="https://social.skynetcloud.site/tags/datatheft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>datatheft</span></a> <a href="https://social.skynetcloud.site/tags/Malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Malware</span></a> <a href="https://social.skynetcloud.site/tags/Spyware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Spyware</span></a> <a href="https://social.skynetcloud.site/tags/VBS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VBS</span></a></p>
JdeBP<p><span class="h-card" translate="no"><a href="https://mastodon.social/@Edent" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Edent</span></a></span> </p><p>It is a shame that neither</p><p>&gt; Resolve-DnsName -Name where-is-the-iss.dedyn.io -Type LOC</p><p>nor</p><p>&gt; nslookup -type=loc where-is-the-iss.dedyn.io</p><p>work.</p><p>Not even <span class="h-card" translate="no"><a href="https://mastodon.social/@rmbolger" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rmbolger</span></a></span> 's Resolve-Dns supports the LOC resource record type.</p><p>Although I suspect that might be the Windows tool that gains support the most quickly, just for the bragging rights of being able to show an ISS LOC record in Windows when no-one else can. (-:</p><p><a href="https://mastodonapp.uk/tags/PowerShell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerShell</span></a> <a href="https://mastodonapp.uk/tags/DNS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DNS</span></a> <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodonapp.uk/tags/nslookup" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nslookup</span></a></p>
Scripter :verified_flashing:<p>Microsoft Windows: Nutzerzahlen brechen massiv ein<br><a href="https://www.t-online.de/digital/aktuelles/id_100799194/microsoft-windows-nutzerzahlen-brechen-massiv-ein.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">t-online.de/digital/aktuelles/</span><span class="invisible">id_100799194/microsoft-windows-nutzerzahlen-brechen-massiv-ein.html</span></a> <a href="https://social.tchncs.de/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://social.tchncs.de/tags/Betriebssystem" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Betriebssystem</span></a> <a href="https://social.tchncs.de/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://social.tchncs.de/tags/Nutzerzahlen" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Nutzerzahlen</span></a></p>
JdeBP<p><span class="h-card" translate="no"><a href="https://techhub.social/@zombiewarrior" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>zombiewarrior</span></a></span> <span class="h-card" translate="no"><a href="https://plush.city/@kebokyo" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>kebokyo</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.neilzone.co.uk/@neil" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>neil</span></a></span> </p><p>If they truly did nothing, that would probably be better.</p><p>What they actually do is turn the setting off where most people test it to check that it is doing what it claims, i.e. running a WWW browser or suchlike application interactively, whilst covertly leaving it on in non-interactive but pretty serious parts of the system.</p><p>Until one day you fiddle with the <a href="https://mastodonapp.uk/tags/ProxyAutoConfiguration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ProxyAutoConfiguration</span></a> file, thinking that it's not in use, and you find that your supposedly dummy HTTP server is getting a lot of requests.</p><p><a href="https://mastodonapp.uk/@JdeBP/114696051410902443" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mastodonapp.uk/@JdeBP/11469605</span><span class="invisible">1410902443</span></a></p><p><a href="https://mastodonapp.uk/tags/WPAD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WPAD</span></a> <a href="https://mastodonapp.uk/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a></p>
JdeBP<p><span class="h-card" translate="no"><a href="https://plush.city/@kebokyo" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>kebokyo</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.neilzone.co.uk/@neil" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>neil</span></a></span> </p><p>My biggest security concern this year wasn't anything to do with my static content servers, or even the machine they are running on, at all.</p><p>It was the fact that if one turns off WWW Proxy Auto Discovery in <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> system settings, it turns out not to actually turn it off for some fairly vital things like the auto-updates for Windows and Office.</p><p>Top <a href="https://mastodonapp.uk/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> tip: Act as if <a href="https://mastodonapp.uk/tags/WPAD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WPAD</span></a> is always on, because it turns out that it is.</p><p><a href="https://mastodonapp.uk/tags/ProxyAutoConfiguration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ProxyAutoConfiguration</span></a></p>
Aptivi<p>Microsoft releases the June 2025 preview patch for Windows 11!</p><p><a href="https://mastodon.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://mastodon.social/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://mastodon.social/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodon.social/tags/Computers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Computers</span></a> <a href="https://mastodon.social/tags/Laptops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Laptops</span></a> <a href="https://mastodon.social/tags/TechNews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechNews</span></a> <a href="https://mastodon.social/tags/TechUpdates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechUpdates</span></a></p><p><a href="https://officialaptivi.wordpress.com/2025/06/28/windows-11-june-2025-preview-patch-is-out/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">officialaptivi.wordpress.com/2</span><span class="invisible">025/06/28/windows-11-june-2025-preview-patch-is-out/</span></a></p>
JdeBP<p><span class="h-card" translate="no"><a href="https://mas.to/@mroach" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mroach</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.scot/@ColinHaynes" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ColinHaynes</span></a></span> </p><p>In the meantime, Microsoft tried to ruin everyone's fun by making Windows NT 10.0 be the same version number as used by the marketing people.</p><p>But it's alright. It has slipped again. Windows NT version 10.0.26100 is is not called that by the marketing people.</p><p>One is not immune in the non-Microsoft world, though. Place these in the correct order:</p><p>Buster<br>Etch<br>Forky<br>Jessie<br>Potato<br>Sarge<br>Sid<br>Wheezy<br>Trixie</p><p>(-:</p><p><a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodonapp.uk/tags/WindowsNT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WindowsNT</span></a> <a href="https://mastodonapp.uk/tags/Debian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Debian</span></a></p>
.:\dGh/:.<p>Yes, especially when <a href="https://mastodon.social/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> decides to fuck you over and not boot... AT ALL.</p><p>I'll recommend a <a href="https://mastodon.social/tags/Mac" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Mac</span></a> to anyone, and one good flavour of Linux to the poorer/developers ones.</p><p><a href="https://mastodon.social/tags/PC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PC</span></a> <a href="https://mastodon.social/tags/Computer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Computer</span></a> <a href="https://mastodon.social/tags/Computers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Computers</span></a> <a href="https://mastodon.social/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://mastodon.social/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodon.social/tags/OS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OS</span></a></p>
JdeBP<p><span class="h-card" translate="no"><a href="https://cyberplace.social/@WiteWulf" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>WiteWulf</span></a></span> </p><p>Something, something, LibreOffice? (-:</p><p>Children nowadays, eh?</p><p>You wait until that old driver cleanout happens that Microsoft was warning about the future possibility of recently, and xe finds that suddenly the old Windows drivers for secondhand <a href="https://mastodonapp.uk/tags/Dell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Dell</span></a> hardware aren't available, only new ones for current hardware.</p><p><a href="https://techcommunity.microsoft.com/blog/hardwaredevcenter/removal-of-unwanted-drivers-from-windows-update/4425647" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">techcommunity.microsoft.com/bl</span><span class="invisible">og/hardwaredevcenter/removal-of-unwanted-drivers-from-windows-update/4425647</span></a></p><p><a href="https://mastodonapp.uk/tags/LibreOffice" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LibreOffice</span></a> <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a></p>
JdeBP<p>My educated first guess is that this is some side-effect on the proxy settings of Session 0 Isolation, or HKLM versus HKCU, or something.</p><p>Certainly all of the session 1 programs running on the desktop as the logged-in user appear to be obeying the proxy settings shown in System Settings. The HTTP server pointed to by the PAC file isn't getting any hijacked traffic from any WWW browsers, or from Electron(-like) apps.</p><p><a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodonapp.uk/tags/WPAD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WPAD</span></a> <a href="https://mastodonapp.uk/tags/ProxyAutoConfiguration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ProxyAutoConfiguration</span></a> <a href="https://mastodonapp.uk/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p>
JdeBP<p>I've run ktrace/truss on the HTTP server as the easiest way to find out what requests it was receiving, given that they're either being conveniently downgraded from HTTPS to a CONNECT over HTTP, or were in HTTP already.</p><p>There is good news and there is bad news.</p><p>The good news is that there's nothing particularly new amongst the URLs. Microsoft discloses a lot, but not all, of them. A couple belong to other companies, but the connections to Microsoft, Google, et al. are overt.</p><p>The bad news is that these are things like certificate revocation lists from Google, other certificate information, your Microsoft account login on Windows Live, Bing Maps, Windows Defender updates, and various other stuff. And they're all vulnerable to a WPAD attack on an untrusted LAN (e.g. your favourite Internet café) that has been known about for over 20 years.</p><p>And, importantly, that the system administrator *thinks is turned off*.</p><p><a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodonapp.uk/tags/WPAD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WPAD</span></a> <a href="https://mastodonapp.uk/tags/ProxyAutoConfiguration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ProxyAutoConfiguration</span></a> <a href="https://mastodonapp.uk/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p>
Alan Lewis<p>MICROSOFT WINDOWS<br>Mastodon Post</p><p>Did anyone other than me get a really weird survey from Windows today or anytime recently?</p><p>They asked the sorts of questions that might have pertained to the unstable Windows Millennium Edition a quarter century ago.</p><p>I wonder what problems are being reported or anticipated.</p><p>The questions gave me the idea that Windows Team members don't know what they are doing and I hardly needed to be GIVEN that idea. It was already readily apparent.</p><p>: <a href="https://c.im/tags/computers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>computers</span></a> <a href="https://c.im/tags/microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>microsoft</span></a> <a href="https://c.im/tags/microsoftwindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>microsoftwindows</span></a> <a href="https://c.im/tags/windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windows</span></a> <a href="https://c.im/tags/windows10" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windows10</span></a> <a href="https://c.im/tags/windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windows11</span></a> <a href="https://c.im/tags/windowsme" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windowsme</span></a> <a href="https://c.im/tags/windowsos" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windowsos</span></a> :</p>
JdeBP<p>The hijacking method itself isn't new, by the way. I wrote about trusting DHCP servers back in 2004. I control what my DHCP server hands out in leases, and I also control what wpad.$searchdomain on my LAN is.</p><p>So it's not that this <a href="https://mastodonapp.uk/tags/WPAD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WPAD</span></a> hijacking is possible. It's that for some parts of <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> it is apparently impossible *to prevent* by turning off automatic proxy setup.</p><p>For parts of the system that are pulling the wpad.dat file every half hour, and appear to be doing things with trust certificates, over HTTP.</p><p><a href="https://jdebp.uk/FGA/web-browser-auto-proxy-configuration.html#Security" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">jdebp.uk/FGA/web-browser-auto-</span><span class="invisible">proxy-configuration.html#Security</span></a></p><p><a href="https://mastodonapp.uk/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p>
JdeBP<p>There's something inside <a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> that does not respect the system settings and *always* uses Web Proxy Auto-Discovery.</p><p>I have WPAD turned off on my Windows machines, and recently fiddled with the LAN's wpad.dat thinking that nothing would be using it, making it point to a dummy proxy.</p><p>The dummy proxy is currently logging a lot of repetitive HTTP requests coming in from what appear to be internal Microsoft services. I've seen digicert.com. , pki.goog. , and cdn.office.net. URLs, so far. I've tested the WWW browsers, and they're definitely respecting the system proxy settings.</p><p>It's not that these requests are being made. It's that they're being routed as instructed by a PAC file where a system administrator has *turned off WPAD* because of its vulnerability to hijacking by whoever controls DHCP/proxy DNS on the LAN. I just hijacked myself. Others are probably not so lucky.</p><p><a href="https://mastodonapp.uk/tags/WPAD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WPAD</span></a> <a href="https://mastodonapp.uk/tags/ProxyAutoConfiguration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ProxyAutoConfiguration</span></a> <a href="https://mastodonapp.uk/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p>
JdeBP<p>"I know a bit about Windows." I thought to myself. "I do not actually have to reboot to get this change to be recognized. I can just stop and restart the service. All of this stuff about needing to reboot all of the time is not entirely right."</p><p>Of course, the SCM then goes and reports that it is unable to stop the service.</p><p>Gah!</p><p><a href="https://mastodonapp.uk/tags/MicrosoftWindows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MicrosoftWindows</span></a> <a href="https://mastodonapp.uk/tags/ServiceControlManager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ServiceControlManager</span></a></p>