Windows Xp Passwords Rendered Useless

0,3363,i=16271,00.gif

Windows guru Brian Livingston reports that inserting a Windows 2000 CD into an XP system allows one to bypass all password protection and manipulate any part of the machine at will. "Anyone with a Windows 2000 CD can boot up a Windows XP box and start the Windows 2000 Recovery Console," says Livingston. The intruder has Administrator privileges even if he or she does not provide a password, and can also assume the identity of any other user of the machine.

"I notified four Microsoft executives of the XP flaw weeks ago, but haven't yet received an official response," writes Livingston. "There's no Knowledge Base article about it, and there may not even be a good solution to the problem."

While one does need physical access to the machine to exploit the flaw, this will be little comfort to the administrators of academic computer laboratories and other facilities where users can easily pop a CD-ROM into a computer

#15945

But what does that mean? Windows2000 and XP cannot run from a CD since the booting process must be able to write data if that were possible we would all have a CD or DVD that could boot WindowsXP or 2000 and run from a nice interface to do whatever de-bugging we need. Microsoft has extensive papers saying this is not possible. All you could do is trigger the re-installation of one OS on top of the other or repair any missing files. I'm not sure this will allow you to get access to the Windows machine and snoop around. You might as well boot from a floppy DOS and do your snooping or work.

Why don't you give it a shot and let us know, since we would all be interested in this.

Thanks

#15948

Yes but nce you get into Recovery Console with Administrator rights you can basically do anything you want. You can even change the administrator password or create new accounts with which you can boot into the Windows GUI...

Siddharth

#15989

Don't you need to know the password to change it or even create a new account? Either way you need to get Administrator Rights which I doubt you can in such a straight forward way, simply by inserting a Windows2000 CD.

#15990

Go read the comments on this story at slashdot.org and osnews.com and see that tricks like this can be done with any OS practically.

And not just with a win2k disk you can use a disk like knoppix or something.

*nix: Or boot into single user mode.

OSX: You can mount a OSX box as a drive on another one etc. Or use the install CD

The moral of this story is if the person has physical access to your computer then all bets are off. Heck they could just take it and dissect it at their leisure.

And yes I know about a boot disk this is in no way a comprehensive list of ways my main point is that similar things can be done on all OS' just read the comments in the above mentioned sites.

#15991

Smoke ....but that is also possible with a DOS floppy too.

O.K. , I read several posts and it does not seem a big deal in most cases for most users. If the Administrator account is password protected you are going to need a password according to people that tried it before you ever get such rights. Passwords can be cracked if you have the time and the know-how but you gotta spend a long time. Second if it is a matter of copying files or messing up a computer you can do it on any Windows machine with a floppy boot since the time of DOS. Nothing new here.

#15992