Feeds

Small WinXP security glitch, not many dead

Silly tricks with Win2k CDs?

  • alert
  • submit to reddit

High performance access to file storage

A glitch in Windows XP security allows you to bypass passwords and gain access to a machine using a Windows 2000 CD, reports the newsletter Brian's Buzz. Of course in order to use the CD you need to have physical access to the machine already, so this is a pretty pointless glitch - it is, however, a glitch.

It works like this. If you boot an XP machine using the Win2k distribution CD and start the recovery console, you can then get into it, copy and change files without needing a password. This doesn't work using the XP recovery console with XP, nor using the Win2k console with Win2k,so it's clearly an oopsie.

But on the other hand, if we're not talking encrypted file systems here (which we're not), then so long as you've got an innocent PC running any old operating system at your mercy you can surely get in there. With Win2k or XP it doesn't take a whole lot of expertise to just use the distribution CD to reinstall the OS, and then it's all yours anyway.

So in this case, we figure the only effects are that it gets round a bit of window dressing style security which doesn't do much more than stop the unlettered breaking in, and it helps dispel any illusory feeling of security similarly unlettered users might have.

Which is good, in its own small way. But getting a high security PC where your password (or perhaps your smartcard or your - shudder - Microsoft watch) actually means much, and which is capable of repelling the technically astute office cleaner, is an entirely different matter. Not that we think many of you will like it when you get it, anyway. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Inside the Hekaton: SQL Server 2014's database engine deconstructed
Nadella's database sqares the circle of cheap memory vs speed
Oh no, Joe: WinPhone users already griping over 8.1 mega-update
Hang on. Which bit of Developer Preview don't you understand?
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
IRS boss on XP migration: 'Classic fix the airplane while you're flying it attempt'
Plus: Condoleezza Rice at Dropbox 'maybe she can find ... weapons of mass destruction'
Ditch the sync, paddle in the Streem: Upstart offers syncless sharing
Upload, delete and carry on sharing afterwards?
New Facebook phone app allows you to stalk your mates
Nearby Friends feature goes live in a few weeks
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.