RE: [in] Re: [Full-Disclosure] IE is just as safe as FireFox

From: Paul Schmehl (pauls_at_utdallas.edu)
Date: 11/19/04

  • Next message: Christian Fromme: "Re: [Full-Disclosure] Why is IRC still around?"
    To: full-disclosure@lists.netsys.com
    Date: Fri, 19 Nov 2004 16:19:49 -0600
    
    

    --On Friday, November 19, 2004 01:12:31 PM -0500 "Crotty, Edward"
    <Edward.Crotty@dowjones.com> wrote:

    > I'm not a Win based guy (troll?) - Un*x here - and even I was offended by
    > #1.
    >
    > There is such a thing as "runas" for Windows.
    >
    That's not all.

    > -----Original Message-----
    > From: full-disclosure-admin@lists.netsys.com
    > [mailto:full-disclosure-admin@lists.netsys.com]On Behalf Of devis
    > Sent: Friday, November 19, 2004 11:10 AM
    > Cc: full-disclosure@lists.netsys.com
    > Subject: Re: [in] Re: [Full-Disclosure] IE is just as safe as FireFox
    >
    > 1) Despite recent ameliorations of MS ( multi user finally, permissions
    > ... ) and some effort at making the system more secure, something very
    > important is still left out: The first default user of the MS computer
    > is made an administrator.

    Apparently you don't have very broad experience with OSes. ON *every* OS
    I'm familiar with, the first user is the administrator (or root) account.

    > This comes down to giving uid0 to ur first
    > unix user. Unix does NOT do that. It requieres you to use su and become
    > root ( administrator ) after proper credentials submission ( password ).

    When's the last time you installed an OS from scratch? Gentoo, FreeBSD,
    OpenBSD, RedHat, Fedora, Slackware, Mac OS X, Debian, Solaris, *all* create
    the first user as uid0 during the install process. (I can't speak for the
    others because I haven't done those, but I'd be willing to bet that NetBSD,
    AIX, HP-UX, SCO et. al. work exactly the same way.)

    Unix does not grant users root access by default, and it does a much better
    job of separating privileges by requiring you to join the wheel group *and*
    either use sudo or su to do work as root, but Windows doesn't make users
    the admin by default *either*, unless you setup Fast User Switching
    *during* the install.

    > The first user is NOT and administrator, and any recent Unix
    > documentation will insist on the danger of running as root(admin). Unix
    > keeps the admin account well separated from the user account, which MS
    > DOESN'T,

    That's simply false. Windows has several groups. By default users are in
    the "USERS" group, *not* the ADMINISTRATORS group.

    It might make sense if you actually had knowledge of an OS before you
    criticize it.

    > Please install a proper unix, create 2 accounts and try to
    > read the home directory of the second user from the first.
    >
    Please do the same in Windows. Here's a hint. You'll get the same results.

    > 2) "After all, they don;t need to know" . " You're on a need to know
    > basis job"
    > Do MS really think the users are stupid ?

    Probably. Otherwise they wouldn't have those stupid warnings popup every
    time you try to delete something. Are you SURE you want to do this????
    Yes, damn it!!
    >
    [snipped the rant]
    >
    > Lets not hide from ourselves whats needed from MS to reach modern world
    > security:
    > a complete rewrite, and a ditch of old Dos base and the 20 years old
    > legacy code.
    >
    Oh baloney. Learn a little more about the OS before you make assumptions
    that make you look ignorant.

    Aside from the default permissions, you can also granularly apply
    privileges in many ways. For example, by default USERS have Read &
    Execute, List Folder Contents and Read access to the Windows folder, its
    contents and all it's subfolders. In addition, there are fourteen (14)
    separate rights that can be explicity granted or denied to them at that
    level only or to all subfolders as well, to files only, to subfolders only,
    to subfolders *and* files only, etc., etc.

    I'm not Windows fan, but the least you can do is learn the subject before
    you claim expert status and presume to preach to others.

    While we're lecturing the unwashed, would you mind trimming your replies?
    Who needs six levels of FD disclaimers?

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Christian Fromme: "Re: [Full-Disclosure] Why is IRC still around?"

    Relevant Pages

    • Re: Login
      ... Comparing the antiquated Unix permissions model to the more modern ... Windows NT access control mechanisms is ... the SYSTEM account is the ... analog to the Administrator account, ...
      (comp.unix.bsd.freebsd.misc)
    • Re: WinNT/2000 screen saver with password and Logoff?
      ... This may be one of the few instances where Windows security ... surpasses that of Unix. ... But I can't give the users blanket Administrator rights. ...
      (microsoft.public.win2000.security)
    • Re: WinNT/2000 screen saver with password and Logoff?
      ... This may be one of the few instances where Windows security ... surpasses that of Unix. ... But I can't give the users blanket Administrator rights. ...
      (comp.os.ms-windows.nt.admin.security)
    • Re: SFU3.5 and getting permissions to work
      ... windows out to unix, not unix into windows... ... >You associate a Windows user (eg administrator) with a Unix ... >user (eg root). ...
      (microsoft.public.win2000.active_directory)
    • Re: What is the more popular UNIX flavor?
      ... about my experience with Solaris and Cygwin. ... installing packages. ... needing eg tftp you only need to activate on a Unix system. ... probably need installing first on the equivalent Windows system. ...
      (comp.unix.questions)