{"id":5678,"date":"2018-12-16T01:33:12","date_gmt":"2018-12-16T01:33:12","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=5678"},"modified":"2018-12-16T01:33:13","modified_gmt":"2018-12-16T01:33:13","slug":"i-fought-the-autoruns-and-autoruns-won","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2018\/12\/16\/i-fought-the-autoruns-and-autoruns-won\/","title":{"rendered":"I fought the Autoruns, and Autoruns won&#8230;"},"content":{"rendered":"\n<p>One of the less visible aspects of security research are constant failures. Anyone who &#8216;pokes around&#8217; fails a lot. I covered some of my research fails in the past, so in a humble attempt to continue this tradition I am writing another quick post about&#8230; well&#8230; yet another fail.<\/p>\n\n\n\n<p>The test I came up with was based on the following:<br>&#8211; Anytime you disable an autorun entry, it is being removed from the startup location, and migrated to the &#8216;AutorunsDisabled&#8217; bucket &#8211; either created as a Registry key or a Folder<br><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won0.png\" alt=\"\" class=\"wp-image-5679\" width=\"378\" height=\"89\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won0.png 626w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won0-300x71.png 300w\" sizes=\"(max-width: 378px) 100vw, 378px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won1.png\" alt=\"\" class=\"wp-image-5680\" width=\"387\" height=\"90\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won1.png 645w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won1-300x70.png 300w\" sizes=\"(max-width: 387px) 100vw, 387px\" \/><\/figure><\/div>\n\n\n\n<p>&#8211; I thought, what if I create an entry, mark it as disabled in Autoruns (forcing it to be moved to the &#8216;AutorunsDisabled&#8217; bucket), and then re-add it in the same place. Without reverse-engineering the Autoruns I was hypothesizing there is a possibility that a presence of &#8216;AutorunsDisabled&#8217; Registry key, or respective Folder will prevent Autoruns from displaying the entry in Autoruns, or will somehow affect the logic of this display.<br><\/p>\n\n\n\n<p>I was wrong. A quick test confirmed that when both entries are present, Autoruns simply displays them all:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" loading=\"lazy\" width=\"496\" height=\"100\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won.png\" alt=\"\" class=\"wp-image-5683\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won.png 496w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2018\/12\/autoruns_won-300x60.png 300w\" sizes=\"(max-width: 496px) 100vw, 496px\" \/><\/figure>\n\n\n\n<p>I fought the Autoruns, and Autoruns won&#8230;<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the less visible aspects of security research are constant failures. Anyone who &#8216;pokes around&#8217; fails a lot. I covered some of my research fails in the past, so in a humble attempt to continue this tradition I am &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2018\/12\/16\/i-fought-the-autoruns-and-autoruns-won\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[80],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/5678"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=5678"}],"version-history":[{"count":2,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/5678\/revisions"}],"predecessor-version":[{"id":5684,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/5678\/revisions\/5684"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=5678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=5678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=5678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}