Close

Results 1 to 3 of 3
  1. #1
    DF VIP Member PimpMasterT's Avatar
    Join Date
    Jan 2002
    Location
    0.0.0.0 x 255.255.255.255 --- The Nexus of the Universe
    Posts
    229
    Thanks
    0
    Thanked:        0
    Karma Level
    0

    Default Bypass XP/2k pass

    http://www.theregister.co.uk/content/4/29342.html

    read this article just enough info on how to do it


    please pm 4me2, ABCMan or Czarjunkie with an explanation why you failed to post or request help posting the email headers of the email you mentioned (along with the full headers) too late Ive banned him after no response for 48 hours (4me2)

  2. #2
    DF VIP Member
    unclex's Avatar
    Join Date
    Nov 2000
    Location
    MARS
    Posts
    2,070
    Thanks
    18
    Thanked:        38
    Karma Level
    401

    Default

    XP passwords rendered useless

    By Brian Livingston

    Windows XP, which has been marketed by Microsoft as "the most secure version ever," has been found to have a flaw so bone-headed that it renders passwords ineffective as a means of keeping people out of your PC.

    Reader Tony DeMartino alerted me to the problem, which all administrators of Windows XP machines should immediately take to heart:
    Anyone with a Windows 2000 CD can boot up a Windows XP box and start the Windows 2000 Recovery Console, a troubleshooting program.

    Windows XP then allows the visitor to operate as Administrator without a password, even if the Administrator account has a strong password.

    The visitor can also operate in any of the other user accounts that may be present on the XP machine, even if those accounts have passwords.

    Unbelievably, the visitor can copy files from the hard disk to a floppy disk or other removable media - something even an Administrator is normally prevented from doing when using the Recovery Console.
    This problem is unrelated to a feature of XP that allows an Administrator to set up automatic logon when the Recovery Console is used. Even without the Registry entry that enables this, XP is vulnerable. (For info on that feature, see support.microsoft.com/?scid=kb;en-us;312149.)

    Windows 2000, of course, doesn't allow Recovery Console users to access a hard drive without a password, if one previously existed.

    I notified four Microsoft executives of the XP flaw weeks ago, but haven't yet received an official response. There's no Knowledge Base article about it, and there may not even be a good solution to the problem.

    When I've spoken with Microsoft security pros about similar problems in the past, they've referred me to a company policy that says, "If a bad guy has unrestricted physical access to your computer, it's not your computer anymore."

    That's all well and good - but the fact remains that Windows 2000 doesn't allow anyone with an old CD to get password-free access, and Windows XP does.

    My recommendation: If you use XP machines in open spaces, put the PCs behind a locked door or put a lock on the PCs themselves. The bad guys know about this flaw, and it's just one more thing for the good guys to protect against.



    well noticed

    Have Fun.





    U.N.C.L.E. X

    More UNCLEX than last week but less next :woot:

  3. #3
    DF VIP Member Aido's Avatar
    Join Date
    Jan 2001
    Location
    Carioca, Pragu
    Posts
    1,851
    Thanks
    1
    Thanked:        1
    Karma Level
    360

    Default

    To be fair as soon as anyone gets physical access to your server you're ****ed anyway..

    Even without stuff like this they can use something like NTPasswd or Locksmith to just change the passwords, as soon as you've got physical access to a box you can forget about security as it's gone out the window

    This applies to most Operating Systems as well, not just Windows - even certain Linux builds are affected
    Go shagging in Prague or live it large in Vegas !!

Similar Threads

  1. Moodlogic bypass?
    By sonar in forum Music Factory
    Replies: 0
    Last Post: 16th October 2002, 05:04 PM
  2. how many trys did it take you to pass your driving test ?
    By jjcool in forum The Dog and Duck
    Replies: 63
    Last Post: 14th September 2002, 04:34 PM
  3. Police Report, read and pass on!
    By biggy7 in forum The Dog and Duck
    Replies: 3
    Last Post: 3rd September 2002, 01:00 PM
  4. Any got a key pass?
    By magic1 in forum PC Gaming
    Replies: 3
    Last Post: 1st September 2002, 11:26 AM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •