RE: Windows XP Guest Account.

From: Keith (keith_at_keithbergen.com)
Date: 07/20/03

  • Next message: Curt Purdy: "RE: Cisco IOS Denial of Service that affects most Cisco IOS routers- requires power cycle to recover"
    To: <incidents@securityfocus.com>
    Date: Sun, 20 Jul 2003 09:21:35 -0400
    
    

    Look in the Event Viewer - Security log. I just turned my guest account off
    and on. It logged an event for each. The off event was a "528" and the on
    event was a "538". While the event logs are not very user friendly, you may
    be able to gain some information from it. Also, you may be able to trace
    back some events to see if there are any other logins that are turning guest
    back on.

    Regards,
    Keith.

    Oh, congratulations in advance to all those that are on vacation, and have
    been too inconsiderate to turn off their "out of office assistant" for this
    list.

    -----Original Message-----
    From: Maher Odeh [mailto:rax@X-war.org]
    Sent: Sunday, July 20, 2003 3:53 AM
    To: incidents@securityfocus.com
    Subject: Windows XP Guest Account.

    Hello,

    Something really weird keeps happening to me.
    I have installed WinXP SP1, and as usual, I go though manage computer and I
    change and disable users from there, the users I always keep are
    the Administrator account that I rename to admin and the guest account which
    is disabled by default but I give it a long password that I forget just
    In case this account gets enabled, now for my incident .

    I have been using XP for a while now and I keep noticing from while to a
    while the guest account being enabled, so I go back and disable it again
    It happened to me more than once, on a new installed system that's not
    connected to the internet, first thing I install XP and restart the system,
    The guest account is enabled, something is fishy here I'd say . this cant be
    a Trojan as this system is newly installed without internet connection
    So I guess it could be a bug . but I think that there is a need to check it
    more in depth, what do you think ?

    Thanks,

    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    world's premier technical IT security event! 10 tracks, 15 training
    sessions,
    1,800 delegates from 30 nations including all of the top experts, from CSO's
    to
    "underground" security specialists. See for yourself what the buzz is
    about!
    Early-bird registration ends July 3. This event will sell out.
    www.blackhat.com
    ----------------------------------------------------------------------------

    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    world's premier technical IT security event! 10 tracks, 15 training sessions,
    1,800 delegates from 30 nations including all of the top experts, from CSO's to
    "underground" security specialists. See for yourself what the buzz is about!
    Early-bird registration ends July 3. This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------


  • Next message: Curt Purdy: "RE: Cisco IOS Denial of Service that affects most Cisco IOS routers- requires power cycle to recover"

    Relevant Pages

    • Re: permissions anomaly in XP noted by W2K user
      ... John, ... If one used NTFS as the filesystem then it does have the ... mapped to the Guest account. ... > successful if only I could provide some sort of security on the folders he ...
      (microsoft.public.windowsxp.security_admin)
    • RE: Internet security on "hotspots"
      ... there's a setting in the security policy under Network Access where ... Now if we're talking shares, anonymous never did have access in most cases, ... Disabling the guest account - it's been disabled by default since NT 3.5, ...
      (Focus-Microsoft)
    • [NT] Odd Behavior in Windows XP Home (Security Vulnerability, Shares)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Guest account in Windows XP Home Edition and Windows XP Professional ... This could lead to a compromising of the host, since Guest users are able ...
      (Securiteam)
    • Re: Deny Software installation
      ... That's how it is done in XP and if you give out your admin logon, ... it is already turned off in the Guest account. ... Now that you've given up the security you can either change your login ... > Right now the "Guest" account can install software, ...
      (microsoft.public.windowsxp.basics)
    • Re: Deny Software installation
      ... That's how it is done in XP and if you give out your admin logon, ... it is already turned off in the Guest account. ... Now that you've given up the security you can either change your login ... > Right now the "Guest" account can install software, ...
      (microsoft.public.windowsxp.basics)