RE: Another Mac OS X ScreenSaver Security Issue (after Security Update 2003-07-14)

From: CHRIS GRABENSTEIN (LFGRABC_at_LF.VCCS.EDU)
Date: 07/31/03

  • Next message: Fred Noltie: "Re: Another Mac OS X ScreenSaver Security Issue (after Security Update 2003-07-14)"
    Date: Thu, 31 Jul 2003 16:28:46 -0400
    To: <bugtraq@securityfocus.com>
    
    

    That's not really allowing another program to bind the keys. In the case of
    the Netware client, Microsoft's GINA is completely replaced by the NWGINA
    which handles the authentication at that point. It doesn't simply bypass
    MS's GINA unless I'm incredibly misinformed. A malicious user can certainly
    write their own GINA, but I don't think that's on the same level as simply
    remapping some keys. I also don't believe you can have multiple GINAs in use
    at once.

    |-----Original Message-----
    |From: Brian Eckman [mailto:eckman@umn.edu]
    |Sent: Thursday, July 31, 2003 4:08 PM
    |To: Gavin Hanover; bugtraq@securityfocus.com
    |Subject: Re: Another Mac OS X ScreenSaver Security Issue
    |(after Security Update 2003-07-14)
    |
    |
    |Gavin Hanover wrote:
    |> I don't quite agree. Windows uses control-alt-delete as a security
    |> device. It binds those keys as a hotkey in such a way that no other
    |> aplication can replace it.
    <snip>
    |> Gavin
    |
    |
    |Windows does allow others to bind to those hotkeys. The Novell
    |client is
    |a good example. The Novell NDS password can be used to unlock
    |the screen
    |saver, without requiring the Windows password to be entered. Obviously
    |other programs could bypass the Windows authentication as well.
    |
    |Brian
    |--
    |Brian Eckman
    |Security Analyst
    |OIT Security and Assurance
    |University of Minnesota
    |612-626-7737
    |
    |"There are 10 types of people in this world. Those who
    |understand binary and those who don't."
    |
    |


  • Next message: Fred Noltie: "Re: Another Mac OS X ScreenSaver Security Issue (after Security Update 2003-07-14)"

    Relevant Pages

    • Re: Hide Username when pc awakes
      ... system will begin to boot Windows XP Pro. ... There's an important element of security ... User IDs are never designed to be secret, ... Platform Software Development Kit that has GINA samples in it. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: To detect weak or blank password?
      ... I certainly will be careful if I were to do something such as writing a Gina ... I don't know a lot about security, ... > Gina stub to hook MSGina.dll (or any real gina which response for user ... don't leave any security hole when you implement Gina ...
      (microsoft.public.platformsdk.security)
    • Re: How to catch a KeyPress event in word
      ... > Hi Gina, ... > If you are trying to devise a security scheme for Word such that documents ... > prevent all VBA code from running. ... >>> Keep your VBA code safe, sign the ClassicVB petition www.classicvb.org ...
      (microsoft.public.word.vba.general)
    • Re: How to know if a session is locked
      ... The link with security? ... If my Gina has an hidden ... to monitor such messages, will it be a kind of dangerous back door? ... Christophe ...
      (microsoft.public.platformsdk.security)
    • GINA, userinit.exe and Registry
      ... I developped a Gina DLL from the example given in MSDN. ... When a bran-new user tries to login for the first time, ... There should be 6 keys and there is only ... parameters are wrong or missing but I wonder which one... ...
      (microsoft.public.win32.programmer.kernel)

  • Quantcast