Feeds

Small WinXP security glitch, not many dead

Silly tricks with Win2k CDs?

  • alert
  • submit to reddit

Designing a Defense for Mobile Applications

A glitch in Windows XP security allows you to bypass passwords and gain access to a machine using a Windows 2000 CD, reports the newsletter Brian's Buzz. Of course in order to use the CD you need to have physical access to the machine already, so this is a pretty pointless glitch - it is, however, a glitch.

It works like this. If you boot an XP machine using the Win2k distribution CD and start the recovery console, you can then get into it, copy and change files without needing a password. This doesn't work using the XP recovery console with XP, nor using the Win2k console with Win2k,so it's clearly an oopsie.

But on the other hand, if we're not talking encrypted file systems here (which we're not), then so long as you've got an innocent PC running any old operating system at your mercy you can surely get in there. With Win2k or XP it doesn't take a whole lot of expertise to just use the distribution CD to reinstall the OS, and then it's all yours anyway.

So in this case, we figure the only effects are that it gets round a bit of window dressing style security which doesn't do much more than stop the unlettered breaking in, and it helps dispel any illusory feeling of security similarly unlettered users might have.

Which is good, in its own small way. But getting a high security PC where your password (or perhaps your smartcard or your - shudder - Microsoft watch) actually means much, and which is capable of repelling the technically astute office cleaner, is an entirely different matter. Not that we think many of you will like it when you get it, anyway. ®

Boost IT visibility and business value

More from The Register

next story
Chrome browser has been DRAINING PC batteries for YEARS
Google is only now fixing ancient, energy-sapping bug
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Do YOU work at Microsoft? Um. Are you SURE about that?
Nokia and marketing types first to get the bullet, says report
Microsoft takes on Chromebook with low-cost Windows laptops
Redmond's chief salesman: We're taking 'hard' decisions
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
EU dons gloves, pokes Google's deals with Android mobe makers
El Reg cops a squint at investigatory letters
Big Blue Apple: IBM to sell iPads, iPhones to enterprises
iOS/2 gear loaded with apps for big biz ... uh oh BlackBerry
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.