NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Microsoft Reduced Windows Attack Surface via PowerShell

PowerShell for Vista by January 31, 2007

By Marius Oiaga, Technology News Editor

7th of December 2006, 10:11 GMT

Adjust text size:


Back in 2004, when it was still referred to as Monad, and PowerShell was still in early beta stages, Symantec determined that the command line shell could be used as an attack vector by
a variety of malware including viruses, worms and Trojan horses.

With the recent release of PowerShell 1.0 for Windows XP Service Pack 2 and Windows Server 2003, and with upcoming support for Windows Vista due in January 2007 and for Windows Server code-name "Longhorn" later next year, the command-line and scripting language rises inherent security issues.

"Fortunately, since that presentation PowerShell has added a variety of features that mitigate any huge outbreaks of malicious code written in PowerShell. The first and foremost (and simple) feature is the file association for PowerShell files. When double-clicked, PowerShell files aren't executed, but instead are loaded into Notepad. This will prevent the most common vector of infection where a user receives such a file and double-clicks it. Also, by default, even if you execute PowerShell you can't load and run script files without changing the execution policy to allow non-signed scripts to be executed," explained Eric Chien, Symantec Security Response Engineer.

Moreover, although initially it was rumored that PowerShell will be integrated by default into Windows Vista, that will not be the case, further decreasing the attack surface on the operating system. "Final PowerShell testing on Vista could not start until the PowerShell team had Vista RTM code. Our team needs some time for testing to make sure Windows PowerShell 1.0 works correctly on Windows Vista before releasing the final package as we've done for shipping products like Windows Server 2003 and Windows XP. We do expect to have a final Vista package available by Jan. 31, 2007, at the latest, but we are working very hard to deliver it sooner," revealed Microsoft.
Read by 811 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.0/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows PowerShell 1.0 Released

Microsoft Partied Hard Following Vista RTM (Images Included)

Preview of the Vista Media Center Remote

Installing Vista RTM on Virtual PC 2007 Beta

Microsoft Gives Out Free Windows Vista

Vista BillGates Pirate Edition

Microsoft Introduces Windows Vista Readiness Hands on Lab

Window Vista Available for Download Starting November 17!

Windows Vista Countdown

Deleting the Undeletable in Windows Vista

Vista Enterprise - Pirated and Available for Download

Microsoft Application Compatibility Testing

Vista Virtual Search Folders

Vista's Intelligent Heuristic Memory Management System - SuperFetch

The Windows Vista Panel

Microsoft to Scrap 32-bit Products

The Windows Vista Demo Environment

Does Ballmer Have a Tongue Fetish?

Vista Cartoon Commercial Episode One

1 M "Gears Of War" in 2 Weeks

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM