[ ijbswa-Actionsfile feedback-3614932 ] privacy info leaking to redmond

SourceForge.net <[email protected]> Thu, 22 Aug 2013 17:41:28 -0700
Newsgroups gmane.comp.web.privoxy.devel
Message-ID <[email protected]>
Actionsfile feedback item #3614932, was opened at 2013-08-22 06:48
Message generated for change (Comment added) made by diem
You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=460288&aid=3614932&group_id=11118

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: None
Group: None
Status: Open
Resolution: None
Priority: 5
Private: No
Submitted By: felix (kkfelix)
Assigned to: Ian Silvester (diem)
Summary: privacy info leaking to redmond

Initial Comment:
Hello
After installing Emet tool I noticed this in log. Something sends out computer name, model, bios version obviously to allow easy attack.

"GET http://watson.microsoft.com/StageOne/Generic/EMET_40_PKI/iexplore_exe/10_00_9200_16521%20(win8_g/4_0_4913_26121/1/microsoft_com/en-US/8F432885489320234F7CB1428485EA3014C0BCFE.htm?LCID=1020&OS=6.1.7602.3.00010100.1.0.1.17514&SM=Toshiba%20Inc.&SPN=Protege%20S410&BV=1.86&HCU=10430&Queue=1 HTTP/1.1" 200 43



----------------------------------------------------------------------

>Comment By: Ian Silvester (diem)
Date: 2013-08-22 17:41

Message:
Hi Felix,

I hear your concern, but you face a dilemma. You've installed EMET to help
to mitigate against malware attacks, and yet a /feature/ of EMET might
assist a would-be attacker.

Yes you could implement a filter to modify this request to hide the
sensitive details, but in doing so you might negatively affect EMET's
functionality.

Either way, this is a judgement call for you and not something that ought
to be added to the default Privoxy ruleset.

Cheers,

Ian

----------------------------------------------------------------------

Comment By: felix (kkfelix)
Date: 2013-08-22 14:43

Message:
my concern is supplied details may be used to send specific working attack
against computer. Request itself is not malicious but may serve to create
one, for example by some traffic monitoring tool.


----------------------------------------------------------------------

Comment By: Ian Silvester (diem)
Date: 2013-08-22 12:02

Message:
Hi Felix,

Watson is a generic brand Microsoft have long used for their problem
diagnosis tools. I would suggest that it is not malicious but is instead
part of what EMET does to learn in what ways your PC might be vulnerable to
malicious attack; it is referring to a knowledge base at Microsoft
supplying details about your machine.

Kind regards,

Ian

----------------------------------------------------------------------

You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=460288&aid=3614932&group_id=11118

------------------------------------------------------------------------------
Introducing Performance Central, a new site from SourceForge and 
AppDynamics. Performance Central is your source for news, insights, 
analysis and resources for efficient Application Performance Management. 
Visit us today!
http://pubads.g.doubleclick.net/gampad/clk?id=48897511&iu=/4140/ostg.clktrk