QUOTE(pepoluan @ Dec 30 2005, 01:37 AM)
I mean, what's the point of autorun? Even with autorun disabled, you can still right-click on the CD drive icon and sure enough, there's an "AutoPlay" menu item there. I made a shortcut of the CD on the desktop, so I don't need to open Explorer.
Me, I'd rather hunt and open the autorun.inf file, see what it's configured to execute, and run the file myself. Safer, and I get to know what's going on when I insert a CD.
To answer your question, the autorun is just a lesser part of the total digital control master plan.
Stage 1: Activate Windows Scripting Host in all win98 by default so that email start to infect everyone.
Stage 2: Something to do with DCOM that is remotely running activeX object. Again, why is this on by default since 99% of users use local objects?
Stage 3: Looking at a movie in WMP with activated "Automatically download codec" infect you. Guess if the options is on by default...
Stage 4: Simply looking at image in IE or having them on your HD and opening the folder in the Window Explorer (can you get lower than that? files listing infect now!)
http://www.f-secure.com/news/items/news_2005123000.shtmlStage 5-9: Unknown yet but will probably involve the MS RSS feed support and the MS copy of the PDF format (Metro)
Stage 10: Vista operating system that will upon insertion of CD load directly the protection on it without any way to prevent it. The secure platform initiative will do the rest like prevent control panel and drivers modification...
Then a windows update DNS hack with a delayed payload by some random kid will destroy all the machine in the world and pave the way for the US World Firewall, which put simply will request you to register your "access point" with your ISP that will request access to the Master Firewall, allowing you access to good sites even if everything will be logged for our own good. At last, we will know Peace, hahaha.
The Stage 4 is acting right now and like the stage 3 will probably be left unpatched for a long time, just to make sure it can reach enough people.
Reason for all this is that corp all over the planet now need to prevent their employes to do all thoses risky action, so no music, no movies, no email can be left uncheck. When you don't have the money to control everything, you make other peoples do it for you, corps or ISP.
As a side note, do you know that any web site can get the list of your MSN messager contacts if you have javascript activated and the message is open?
Warning: This post contain an acute form of paranoia.
Sorry if I'm off topic.