[Full-Disclosure] Windows user privileges

From: Mike Hoye (mhoye_at_neon.polkaroo.net)
Date: 11/20/04

  • Next message: chris neitzert: "Re: [Full-Disclosure] Why is IRC still around?"
    To: full-disclosure@lists.netsys.com
    Date: Sat, 20 Nov 2004 08:19:22 -0500
    
    

    On Fri, Nov 19, 2004 at 04:19:49PM -0600, Paul Schmehl wrote:
    > Windows has several groups. By default users are in
    > the "USERS" group, *not* the ADMINISTRATORS group.

    On every XP install that I've seen from every major OEM (Dell, Compaq,
    Gateway, etc) fast user switching is on by default and every user is
    an administrator. Not "on most"; on every single one.

    Furthermore, these machines don't have actual XP OS install CDs, they
    usually come with "restore" CDs that just return the PC to this same
    initial state if they're used, which they almost never are.

    I have never seen a home user, that is to say change that setting or
    create a user who is actually just a "User". Not once, ever.

    > It might make sense if you actually had knowledge of an OS before you
    > criticize it.

    I don't think the question should be "why is IRC still around", I think
    the question should be "why is full-disclosure turning into IRC?"

    - Mike Hoye
     

    -- 
    "Buy land. They've stopped making it." - Mark Twain
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: chris neitzert: "Re: [Full-Disclosure] Why is IRC still around?"

    Relevant Pages

    • RE: Why attacker install irc after hacking?
      ... IRC channel. ... attack through owned box/boxes. ... Why attacker install irc after hacking? ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
      (Security-Basics)
    • RE: Why attacker install irc after hacking?
      ... Usually when the hack has installed some malware, it will report back to a specific IRC channel and wait for the owner to enter any commands. ... Why attacker install irc after hacking? ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ... FREE 30-Day Trial of Spy Sweeper Enterprise ...
      (Security-Basics)
    • Re: [fw-wiz] "firewalls are obsolete" rant
      ... and money on an IRC client/environment at all. ... Here they install ... If you do need to include folks from off the network then why not use ... IRC isn't all that efficient at sharing ideas anyway - can't see how ...
      (Firewall-Wizards)
    • Re: "Repair" install over existing XP
      ... I do have newer install CDs with SP3 ... Is there an easy way to do a "repair" installation from the XP SP3 ... How to perform an in-place upgrade of Windows XP ...
      (microsoft.public.windowsxp.general)
    • Re: First-timer buying AS/400 and have questions
      ... > you dont need the install CDs. ... Then use that tape whenever you have to reload ... > You should know that if you have a set of install CDs you can install ... > the OS and languages and use it for 70 days until the install expires. ...
      (comp.sys.ibm.as400.misc)