[ ijbswa-Actionsfile feedback-3614932 ] privacy info leaking to redmond
SourceForge.net <[email protected]> Thu, 22 Aug 2013 17:41:28 -0700
| Newsgroups | gmane.comp.web.privoxy.devel |
|---|---|
| Message-ID | <[email protected]> |
Actionsfile feedback item #3614932, was opened at 2013-08-22 06:48 Message generated for change (Comment added) made by diem You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=460288&aid=3614932&group_id=11118 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: None Group: None Status: Open Resolution: None Priority: 5 Private: No Submitted By: felix (kkfelix) Assigned to: Ian Silvester (diem) Summary: privacy info leaking to redmond Initial Comment: Hello After installing Emet tool I noticed this in log. Something sends out computer name, model, bios version obviously to allow easy attack. "GET http://watson.microsoft.com/StageOne/Generic/EMET_40_PKI/iexplore_exe/10_00_9200_16521%20(win8_g/4_0_4913_26121/1/microsoft_com/en-US/8F432885489320234F7CB1428485EA3014C0BCFE.htm?LCID=1020&OS=6.1.7602.3.00010100.1.0.1.17514&SM=Toshiba%20Inc.&SPN=Protege%20S410&BV=1.86&HCU=10430&Queue=1 HTTP/1.1" 200 43 ---------------------------------------------------------------------- >Comment By: Ian Silvester (diem) Date: 2013-08-22 17:41 Message: Hi Felix, I hear your concern, but you face a dilemma. You've installed EMET to help to mitigate against malware attacks, and yet a /feature/ of EMET might assist a would-be attacker. Yes you could implement a filter to modify this request to hide the sensitive details, but in doing so you might negatively affect EMET's functionality. Either way, this is a judgement call for you and not something that ought to be added to the default Privoxy ruleset. Cheers, Ian ---------------------------------------------------------------------- Comment By: felix (kkfelix) Date: 2013-08-22 14:43 Message: my concern is supplied details may be used to send specific working attack against computer. Request itself is not malicious but may serve to create one, for example by some traffic monitoring tool. ---------------------------------------------------------------------- Comment By: Ian Silvester (diem) Date: 2013-08-22 12:02 Message: Hi Felix, Watson is a generic brand Microsoft have long used for their problem diagnosis tools. I would suggest that it is not malicious but is instead part of what EMET does to learn in what ways your PC might be vulnerable to malicious attack; it is referring to a knowledge base at Microsoft supplying details about your machine. Kind regards, Ian ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=460288&aid=3614932&group_id=11118 ------------------------------------------------------------------------------ Introducing Performance Central, a new site from SourceForge and AppDynamics. Performance Central is your source for news, insights, analysis and resources for efficient Application Performance Management. Visit us today! http://pubads.g.doubleclick.net/gampad/clk?id=48897511&iu=/4140/ostg.clktrk