Twitter Updates




  • Check out these sites




  • Hackers For Charity

    Social Engineer









    December 18, 2009


    Dr. Watson, You are an Evil one…

    Have you ever had a program crash and get the little Dr. Watson popup in windows. I have disabled this feature in just about every computer I have ever used. What Dr. Watson does, is he sends error reports to Microsoft when a program crashes. What you may or may not know, is that he sends whatever it was you were working on in the process. This is a big problem. Especially when you may have been working on an email or some other document that requires to be send through secure channels(like over ssl or such) and for private recipients only. Well friends, that is not the case with Dr. Watson. If you were working on or reading a confidential email that had say, passwords or proprietary information, guess what. That info gets set to Microsoft. Well, to their Dr. Watson web server anyway. While it gets transmitted, its sent in the clear, so if someone happened to intercept said dump, they now have that information as well.

    While this may seem like a paranoid scenario, I had one such crash happen today, so I decided to copy the dump files normally sent to Microsoft. If you block Dr. Watson and the error reporting service, the files get deleted just as fast as they get created, but not until you click the ok to close the windows error. Before you click to close the dump error, go over to your windows temp folder or wherever your temp files are setup for your environment variables, and look for any files or even a folder containing the following:
    appcompat.txt, manifest.txt, xxxx.exe.hdmp and xxxx.exe.mdmp, where xxxx is the name fo the program that crashed. Copy these files and place them on your desktop. You can the reply to the error message and close it out. These temp files will now be deleted, so you have a hard copy on your desktop. Open the dumps in a text editor, and you can see whatever it was you had open at the time or working on, such as emails or whatever. Just 1 more reason to turn off the so called “its a feature, not a flaw” options built into windows….



    del.icio.us|Digg|Furl|ma.gnolia|RawSugar|reddit|Spurl|Google|StumbleUpon







    RSS feed for comments on this post.

    Sorry, the comment form is closed at this time.