[Full-Disclosure] RE: Vulnerability in IBM Windows XP: default hidden Administrator account allows local Administrator access

From: Michael Wilson, Contractor (mwwilson_at_navo.hpc.mil)
Date: 09/17/04

  • Next message: David.Waggoner_at_instinet.com: "[Full-Disclosure] David Waggoner no longer works here."
    To: "Michael Scheidell" <scheidell@secnap.net>, "Chris Norton" <kicktd_list@hotmail.com>, <bugtraq@securityfocus.com>, <vulnwatch@vulnwatch.org>, <full-disclosure@lists.netsys.com>
    Date: Fri, 17 Sep 2004 15:34:09 -0500
    
    

    I guess that means "If you call IBM support and you have changed your local
    administrator password to anything other than blank, then we may not be able
    to help you out of the bind you have gotten yourself into (data loss)".

    IBM had decided that the average user (of their systems) cannot be trusted
    with even knowing about their systems administrative access, much less the
    password.

    Mike Wilson

    -----Original Message-----
    From: Michael Scheidell [mailto:scheidell@secnap.net]
    Sent: Friday, September 17, 2004 3:20 PM
    To: mwwilson@navo.hpc.mil; Chris Norton; bugtraq@securityfocus.com;
    vulnwatch@vulnwatch.org; full-disclosure@lists.netsys.com
    Subject: RE: Vulnerability in IBM Windows XP: default hidden
    Administrator account allows local Administrator access

    yes, my two biggest complaints:

    1) they bypassed telling you there was one
    2) if you knew about it, and wanted to change it, they told you that you
    would lose data if you did!

    (xp manual install recommends that you put a password on it!)

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: David.Waggoner_at_instinet.com: "[Full-Disclosure] David Waggoner no longer works here."

    Relevant Pages